Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.53424
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 167-1 (Konquerer)
Summary:The remote host is missing an update to Konquerer;announced via advisory DSA 167-1.
Description:Summary:
The remote host is missing an update to Konquerer
announced via advisory DSA 167-1.

Vulnerability Insight:
A cross site scripting problem has been discovered in Konquerer, a
famous browser for KDE and other programs using KHTML. The KDE team
reports that Konqueror's cross site scripting protection fails to
initialize the domains on sub-(i)frames correctly. As a result,
Javascript is able to access any foreign subframe which is defined in
the HTML source. Users of Konqueror and other KDE software that uses
the KHTML rendering engine may become victim of a cookie stealing and
other cross site scripting attacks.

This problem has been fixed in version 2.2.2-13.woody.3 for the
current stable distribution (woody) and in version 2.2.2-14 for the
unstable distribution (sid). The old stable distribution (potato) is
not affected since it didn't ship KDE.

Solution:
We recommend that you upgrade your kdelibs package and restart

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2002-1151
BugTraq ID: 5689
http://www.securityfocus.com/bid/5689
Bugtraq: 20020910 KDE Security Advisory: Konqueror Cross Site Scripting Vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=103175850925395&w=2
Caldera Security Advisory: CSSA-2002-047.0
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-047.0.txt
Conectiva Linux advisory: CLA-2002:525
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000525
Debian Security Information: DSA-167 (Google Search)
http://www.debian.org/security/2002/dsa-167
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-064.php
http://www.osvdb.org/7867
http://www.redhat.com/support/errata/RHSA-2002-220.html
http://www.redhat.com/support/errata/RHSA-2002-221.html
http://www.iss.net/security_center/static/10039.php
CopyrightCopyright (C) 2008 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.