PT-2002-1055 · Kde+2 · Kdelibs+24

Published

2002-10-11

·

Updated

2016-10-18

·

CVE-2002-1152

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions kde-i18n-Catalan version 3.0.3 kde-i18n-Danish version 3.0.3 kde-i18n-Czech version 3.0.3 kde-i18n-Chinese-Big5 version 3.0.3 kde-i18n-3.0.3 version 3.0.3 kde-i18n-British version 3.0.3 kde-i18n-Brazil version 3.0.3 kde-i18n-Afrikaans version 3.0.3 kde-i18n-Chinese version 3.0.3 kdelibs version 2.2.2 kdelibs-devel version 2.2.2 kdelibs-sound version 2.2.2 kdelibs-sound-devel version 2.2.2 kdegraphics version 2.2.2 kdegraphics-devel version 2.2.2 kdegraphics version 3.0.3 kdemultimedia version 3.0.3 kdeadmin version 3.0.3 kdevelop version 2.1.3 kdesdk version 3.0.3 kdeutils version 3.0.3 kdeartwork version 3.0.3 kdepim version 3.0.3 kdenetwork version 2.2.2 kdenetwork-ppp version 2.2.2 kdenetwork version 3.0.3 kdebindings version 3.0.3 kaboodle version 3.0.3 kamera version 3.0.3 karm version 3.0.3 kcharselect version 3.0.3 kcoloredit version 3.0.3 qt version 3.0.5 KDE versions 3.0 through 3.0.2
Description The issue affects various packages of the Red Hat Linux operating system, including kde-i18n, kdelibs, kdegraphics, kdemultimedia, kdeadmin, kdevelop, kdesdk, kdeutils, kdeartwork, kdepim, kdenetwork, kdebindings, kaboodle, kamera, karm, kcharselect, kcoloredit, and qt. The vulnerabilities can lead to a breach of confidentiality, integrity, and availability of protected information. Exploitation can be done remotely. Konqueror in KDE 3.0 through 3.0.2 does not properly detect the "secure" flag in an HTTP cookie, which could cause Konqueror to send the cookie across an unencrypted channel.
Recommendations As a temporary workaround, consider disabling the vulnerable components until a patch is available. Restrict access to the vulnerable modules to minimize the risk of exploitation. Avoid using sensitive information in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08019
BDU:2015-08020
BDU:2015-08021
BDU:2015-08022
BDU:2015-08023
BDU:2015-08024
BDU:2015-08026
BDU:2015-08027
BDU:2015-08029
BDU:2015-08034
BDU:2015-08035
BDU:2015-08036
BDU:2015-08037
BDU:2015-08039
BDU:2015-08041
BDU:2015-08044
BDU:2015-08046
BDU:2015-08048
BDU:2015-08050
BDU:2015-08051
BDU:2015-08053
BDU:2015-08055
BDU:2015-08088
BDU:2015-08089
BDU:2015-08090
BDU:2015-08091
BDU:2015-08092
BDU:2015-08094
BDU:2015-08095
BDU:2015-08096
BDU:2015-08097
BDU:2015-08099
BDU:2015-08101
BDU:2015-08104
BDU:2015-08106
BDU:2015-08209
CVE-2002-1152

Affected Products

Konqueror
Red Hat
Kaboodle
Kamera
Karm
Kcharselect
Kcoloredit
Kde-I18N
Kdeadmin
Kdeartwork
Kdebindings
Kdegraphics
Kdegraphics-Devel
Kdelibs
Kdelibs-Devel
Kdelibs-Sound
Kdelibs-Sound-Devel
Kdemultimedia
Kdenetwork
Kdenetwork-Ppp
Kdepim
Kdesdk
Kdeutils
Kdevelop
Qt