kio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning notifications, which allows man-in-the-middle attackers to obtain sensitive information via an invalid certificate.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade kdelibs | Dec 10, 2025 | Jul 16, 2014 |
| Gentoo Linux | — | Upgrade kde-base/kdelibs. | Oct 30, 2017 | Jul 1, 2014 |
| Suse | — | Upgrade kdelibs4Upgrade kdelibs4-coreUpgrade kdelibs4-branding-upstreamUpgrade libksuseinstall1Upgrade libkde4Upgrade libkdecore4 | Dec 18, 2015 | Jul 1, 2014 |
| Ubuntu | — | Upgrade kde4libs | Nov 19, 2024 | Jul 1, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub