CVE-2018-19120: Infoleak
The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
Other sources
Various KDE applications share a plugin system to create thumbnails of various file types for displaying in file managers, file dialogs, etc.
kio-extras contains a thumbnailer plugin for HTML files.
The HTML thumbnailer was incorrectly accessing some content of remote URLs listed in HTML files. This meant that the owners of the servers referred in HTML files in your system could have seen in their access logs your IP address every time the thumbnailer tried to create the thumbnail.
The HTML thumbnailer has been removed in upcoming KDE Applications 18.12.0 because it was actually not creating thumbnails for files at all.
External References:
https://www.kde.org/info/security/advisory-20181012-1.txt
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19120?
CVE-2018-19120 is a vulnerability in the HTML thumbnailer plugin in KDE Applications before 18.12.0 that allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
What is the severity of CVE-2018-19120?
CVE-2018-19120 has a severity level of 7.5 (high).
How does CVE-2018-19120 affect my system?
CVE-2018-19120 affects systems running KDE Applications before version 18.12.0, specifically the HTML thumbnailer plugin, and allows attackers to trigger outbound TCP connections to arbitrary IP addresses, revealing the source IP address.
How can I fix CVE-2018-19120?
To fix CVE-2018-19120, update your KDE Applications to version 18.12.0 or higher.
Where can I find more information about CVE-2018-19120?
More information about CVE-2018-19120 can be found in the following references: [1] [2] [3].