PatchSiren cyber security CVE debrief
CVE-2017-6410 Kde CVE debrief
CVE-2017-6410 is an information-disclosure issue in KDE’s PAC handling. In affected kio and kdelibs versions, a full HTTPS URL could be passed to the PAC FindProxyForURL function, which may expose sensitive data such as Basic Authentication credentials, query strings, or PATH_INFO to a crafted PAC file.
- Vendor
- Kde
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-02
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-02
- Advisory updated
- 2026-05-13
Who should care
Administrators and users running KDE kio before 5.32 or kdelibs before 4.14.30, especially in environments that use PAC files or proxy auto-configuration. Systems that may send URLs containing credentials or other sensitive components are the most relevant.
Technical summary
NVD describes the flaw in kpac/script.cpp: the PAC FindProxyForURL function is called with the full HTTPS URL instead of a sanitized form. Because the URL may include embedded credentials, query parameters, or PATH_INFO, a malicious PAC file can learn information that should not be exposed. NVD maps the weakness to CWE-319 and rates the issue CVSS 3.0 5.5 MEDIUM (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).
Defensive priority
Medium. Patch impacted KDE components promptly if PAC-based proxy handling is used, especially on endpoints that might process URLs with sensitive path or credential data. The impact is confidentiality-only, but the data exposed can be high value.
Recommended defensive actions
- Upgrade KDE kio to 5.32 or later, or kdelibs to 4.14.30 or later, depending on the deployed package set.
- Review proxy auto-configuration usage and determine whether PAC files are trusted and necessary in the affected environment.
- Check whether applications or workflows may place sensitive material in HTTPS URLs, including credentials, query strings, or PATH_INFO.
- Prioritize patching on user-facing endpoints where users may interact with proxy settings or PAC-based network configuration.
- Use the vendor advisory and distribution security notices to confirm the exact fixed package versions for your platform.
Evidence notes
The supplied NVD record states that kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 passes a full HTTPS URL to PAC FindProxyForURL, potentially exposing Basic Authentication credentials, query strings, or PATH_INFO. The same record lists CWE-319 and CVSS 3.0 vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N. The CVE was published on 2017-03-02; the later 2026-05-13 modified timestamp in NVD metadata should not be treated as the disclosure date.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-6410 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-6410
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-6410 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6410
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.kde.org/info/security/advisory-20170228-1.txt
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.