PT-2004-2110 · Kde+1 · Konqueror+2
Waldo Bastian
·
Published
2004-12-15
·
Updated
2017-10-11
·
CVE-2004-1145
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
KDE versions 3.3.1 and earlier
Description:
The issue allows access to restricted Java classes via JavaScript and does not properly restrict access to certain Java classes from the Java applet. This enables remote attackers to bypass sandbox restrictions and read or write arbitrary files.
Recommendations:
For versions 3.3.1 and earlier, consider disabling JavaScript in Konqueror until a patch is available.
Restrict access to Java applets in Konqueror to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kde
Konqueror
Red Hat