PT-2004-2110 · Kde+1 · Konqueror+2

Waldo Bastian

·

Published

2004-12-15

·

Updated

2017-10-11

·

CVE-2004-1145

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: KDE versions 3.3.1 and earlier
Description: The issue allows access to restricted Java classes via JavaScript and does not properly restrict access to certain Java classes from the Java applet. This enables remote attackers to bypass sandbox restrictions and read or write arbitrary files.
Recommendations: For versions 3.3.1 and earlier, consider disabling JavaScript in Konqueror until a patch is available. Restrict access to Java applets in Konqueror to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1145
RHSA-2005:065
RHSA-2005_065

Affected Products

Kde
Konqueror
Red Hat