Information disclosure in kio-extras - CVE-2018-19120
Published: November 14, 2018 / Updated: November 15, 2018
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to an error when the HTML Thumbnailer plug-in creates a thumbnail for HTML files. A remote attacker can access sensitive information, such as the IP address of a targeted system.
Affected software
Fedora
kio-extras
How to mitigate CVE-2018-19120
kio-extras - addressed in versions 17.12.3-1.fc27.1, 18.08.3-1.fc28, 18.08.3-1.fc29