CVE-2018-19120
published 2018-11-29CVE-2018-19120: The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to…
PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.46%
71.0th percentile
The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kio-extras | < kio-extras 4:18.08.3-1 (bookworm) | kio-extras 4:18.08.3-1 (bookworm) |
| kde | kde_applications | < 18.12.0 | 18.12.0 |
| kde | kio-extras | >= 0 < 4:18.08.3-1 | 4:18.08.3-1 |
| kde | kio-extras | >= 0 < 4:18.08.3-1 | 4:18.08.3-1 |
| kde | kio-extras | >= 0 < 4:18.08.3-1 | 4:18.08.3-1 |
| kde | kio-extras | >= 0 < 4:18.08.3-1 | 4:18.08.3-1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2018-19120: kio-extras - The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers ...
vendor_debian·2018·CVSS 7.5
CVE-2018-19120 [HIGH] CVE-2018-19120: kio-extras - The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers ...
The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
Scope: local
bookworm: resolved (fixed in 4:18.08.3-1)
bullseye: resolved (fixed in 4:18.08.3-1)
forky: resolved (fixed in 4:18.08.3-1)
sid: resolved (fixed in 4:18.08.3-1)
trixie: resolved (fixed in 4:18.08.3-1)
GHSA
GHSA-39rp-qwx2-562v: The HTML thumbnailer plugin in KDE Applications before 18
ghsa_unreviewed·2022-05-14
CVE-2018-19120 [HIGH] CWE-200 GHSA-39rp-qwx2-562v: The HTML thumbnailer plugin in KDE Applications before 18
The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
OSV
CVE-2018-19120: The HTML thumbnailer plugin in KDE Applications before 18
osv·2018-11-29·CVSS 7.5
CVE-2018-19120 [HIGH] CVE-2018-19120: The HTML thumbnailer plugin in KDE Applications before 18
The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-19120 kio-extras: HTML Thumbnailer automatic remote file access [fedora-all]
bugzilla·2018-11-13·CVSS 7.5
CVE-2018-19120 [HIGH] CVE-2018-19120 kio-extras: HTML Thumbnailer automatic remote file access [fedora-all]
CVE-2018-19120 kio-extras: HTML Thumbnailer automatic remote file access [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2018-19120 kio-extras: HTML Thumbnailer automatic remote file access
bugzilla·2018-11-13·CVSS 7.5
CVE-2018-19120 [HIGH] CVE-2018-19120 kio-extras: HTML Thumbnailer automatic remote file access
CVE-2018-19120 kio-extras: HTML Thumbnailer automatic remote file access
Various KDE applications share a plugin system to create thumbnails
of various file types for displaying in file managers, file dialogs, etc.
kio-extras contains a thumbnailer plugin for HTML files.
The HTML thumbnailer was incorrectly accessing some content of
remote URLs listed in HTML files. This meant that the owners of the servers
referred in HTML files in your system could have seen in their access logs
your IP address every time the thumbnailer tried to create the thumbnail.
The HTML thumbnailer has been removed in upcoming KDE Applications 18.12.0
because it was actually not creating thumbnails for files at all.
External References:
https://www.kde.org/info/security/advisory-20181012-1.txt
Discussion:
https://bugzilla.redhat.com/show_bug.cgi?id=1649420https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CWRCGXLPJHM4OFD66BINH2FIMYHRCRKF/https://bugzilla.redhat.com/show_bug.cgi?id=1649420https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CWRCGXLPJHM4OFD66BINH2FIMYHRCRKF/
2018-11-29
Published