CVE
- Id
- 103230
- CVE No.
- CVE-2017-6410
- Status
- Candidate
- Description
- kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.
- Phase
- Assigned (20170301)
- Votes
- None (candidate not yet proposed)
- Comments