PT-2004-1056 · Kde+1 · Kdebase-Devel+3

Publicado

2004-12-10

·

Atualizado

2017-10-11

·

CVE-2004-1158

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions kdebase versions 2.2.2 through 3.1.3 kdebase-devel versions 2.2.2 through 3.1.3 Konqueror versions 3.x up to 3.2.2-6
Description The issue concerns multiple vulnerabilities in the kdebase and kdebase-devel packages of Red Hat Enterprise Linux, as well as in Konqueror. These vulnerabilities can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Specifically, Konqueror's "window injection" vulnerability allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain.
Recommendations For kdebase versions 2.2.2 through 3.1.3, update to a version that contains a fix for this issue. For kdebase-devel versions 2.2.2 through 3.1.3, update to a version that contains a fix for this issue. For Konqueror versions 3.x up to 3.2.2-6, consider disabling the ability to inject content from one window into another as a temporary workaround until a patch is available.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06209
BDU:2015-06210
BDU:2015-06211
BDU:2015-06212
CVE-2004-1158
RHSA-2005:009
RHSA-2005_009

Produtos afetados

Konqueror
Red Hat
Kdebase
Kdebase-Devel