Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.53890
Categoría:Slackware Local Security Checks
Título:Slackware: Security Advisory (SSA:2003-213-01)
Resumen:The remote host is missing an update for the 'KDE' package(s) announced via the SSA:2003-213-01 advisory.
Descripción:Summary:
The remote host is missing an update for the 'KDE' package(s) announced via the SSA:2003-213-01 advisory.

Vulnerability Insight:
New KDE packages are available for Slackware 9.0. These address a
security issue where Konqueror may leak authentication credentials.


Here are the details from the Slackware 9.0 ChangeLog:
+--------------------------+
Fri Aug 1 15:15:51 PDT 2003
patches/packages/kde/*: Upgraded to KDE 3.1.3.
Note that this update addresses a security problem in Konqueror which may
cause authentication credentials to be leaked to an unintended website
through the HTTP-referer header when they have been entered into Konqueror
as a URL of the form:
http://user:password@example.com/
For more information about this issue, please see the KDE advisory:
[link moved to references]
We recommend that sites running KDE install this update.
(* Security fix *)
patches/packages/kdei/*: New internationalization packages for KDE 3.1.3.
+--------------------------+

Affected Software/OS:
'KDE' package(s) on Slackware 9.0.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2003-0459
Bugtraq: 20030802 [slackware-security] KDE packages updated (SSA:2003-213-01) (Google Search)
http://marc.info/?l=bugtraq&m=105986238428061&w=2
Conectiva Linux advisory: CLA-2003:747
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000747
Debian Security Information: DSA-361 (Google Search)
http://www.debian.org/security/2003/dsa-361
http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/007300.html
http://www.mandriva.com/security/advisories?name=MDKSA-2003:079
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A411
http://www.redhat.com/support/errata/RHSA-2003-235.html
http://www.redhat.com/support/errata/RHSA-2003-236.html
TurboLinux Advisory: TLSA-2003-45
http://www.turbolinux.com/security/TLSA-2003-45.txt
CopyrightCopyright (C) 2012 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.