The vulnerability is caused by KGet downloading files without the user's acknowledgment, overwriting existing files of the same name when displaying a dialog box that allows a user to choose the file to download out of the options offered by a metalink file.
Patch Availability:
Apply patches for the 4.3 and 4.4 branches committed to the KDE Subversion repository.