PT-2004-1056 · Kde+1 · Kdebase-Devel+3

Published

2004-12-10

·

Updated

2017-10-11

·

CVE-2004-1158

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions kdebase versions 2.2.2 through 3.1.3 kdebase-devel versions 2.2.2 through 3.1.3 Konqueror versions 3.x up to 3.2.2-6
Description The issue concerns multiple vulnerabilities in the kdebase and kdebase-devel packages of Red Hat Enterprise Linux, as well as in Konqueror. These vulnerabilities can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Specifically, Konqueror's "window injection" vulnerability allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain.
Recommendations For kdebase versions 2.2.2 through 3.1.3, update to a version that contains a fix for this issue. For kdebase-devel versions 2.2.2 through 3.1.3, update to a version that contains a fix for this issue. For Konqueror versions 3.x up to 3.2.2-6, consider disabling the ability to inject content from one window into another as a temporary workaround until a patch is available.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06209
BDU:2015-06210
BDU:2015-06211
BDU:2015-06212
CVE-2004-1158
RHSA-2005:009
RHSA-2005_009

Affected Products

Konqueror
Red Hat
Kdebase
Kdebase-Devel