PT-2002-1036 · Kde+1 · Kdelibs+7

George Staikos

·

Published

2002-11-27

·

Updated

2017-10-11

·

CVE-2003-0459

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions kdelibs versions 2.2.2 through 3.0.5a kdebase versions 3.0.5a and earlier kdelibs-sound versions 2.2.2 kdelibs-sound-devel version 2.2.2 kdebase-devel version 3.0.5a kdelibs-devel versions 2.2.2 through 3.0.5a
Description The issue concerns multiple vulnerabilities in various packages of the Red Hat Linux operating system, including kdelibs, kdebase, kdelibs-sound, kdelibs-sound-devel, kdebase-devel, and kdelibs-devel. These vulnerabilities can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Specifically, KDE Konqueror for KDE 3.1.2 and earlier does not properly remove authentication credentials from URLs in the HTTP-Referer header, which could allow remote websites to steal these credentials.
Recommendations For kdelibs versions 2.2.2 through 3.0.5a, update to a version later than 3.0.5a to resolve the issue. For kdebase versions 3.0.5a and earlier, update to a version later than 3.0.5a to resolve the issue. For kdelibs-sound versions 2.2.2, update to a version later than 2.2.2 to resolve the issue. For kdelibs-sound-devel version 2.2.2, update to a version later than 2.2.2 to resolve the issue. For kdebase-devel version 3.0.5a, update to a version later than 3.0.5a to resolve the issue. For kdelibs-devel versions 2.2.2 through 3.0.5a, update to a version later than 3.0.5a to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and authentication credentials until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07870
BDU:2015-07871
BDU:2015-08030
BDU:2015-08032
BDU:2015-08088
BDU:2015-08090
BDU:2015-08091
BDU:2015-08092
CVE-2003-0459
DSA-361

Affected Products

Kde Konqueror
Red Hat
Kdebase
Kdebase-Devel
Kdelibs
Kdelibs-Devel
Kdelibs-Sound
Kdelibs-Sound-Devel