PT-2004-1825 · Kde · Konqueror
Published
2004-09-14
·
Updated
2017-10-11
·
CVE-2004-0746
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Konqueror in KDE versions 3.2.3 and earlier
Description
The issue allows web sites to set cookies for country-specific top-level domains. This could enable remote attackers to perform a session fixation attack and hijack a user's HTTP session.
Recommendations
For Konqueror in KDE versions 3.2.3 and earlier, consider disabling the cookie setting feature for country-specific top-level domains until a patch is available. Restrict access to sensitive web sites to minimize the risk of session fixation attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Konqueror