PT-2004-1825 · Kde · Konqueror

Published

2004-09-14

·

Updated

2017-10-11

·

CVE-2004-0746

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Konqueror in KDE versions 3.2.3 and earlier
Description The issue allows web sites to set cookies for country-specific top-level domains. This could enable remote attackers to perform a session fixation attack and hijack a user's HTTP session.
Recommendations For Konqueror in KDE versions 3.2.3 and earlier, consider disabling the cookie setting feature for country-specific top-level domains until a patch is available. Restrict access to sensitive web sites to minimize the risk of session fixation attacks.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0746
RHSA-2004:412

Affected Products

Konqueror