LWN.net Logo

Cross-site scripting vulnerability in Konqueror for KDE 3.0.3

Package(s):kdelibs CVE #(s):
Created:September 17, 2002 Updated:November 18, 2002
Description: Konqueror for KDE 3.0.3, and earlier versions, is subject to this cross-site scripting vulnerability. Since the problem is in kdelibs, any other application which uses the KHTML renderer is also vulnerable. Javascript code running in one frame can access other frames which should be inaccessible. The problem is fixed in kdelibs 3.0.3a.
Alerts:
SCO Group CSSA-2002-047.0 2002-11-15
Mandrake MDKSA-2002:064 2002-10-09
Conectiva CLA-2002:525 2002-09-20
Debian DSA-167-1 2002-09-16

(Log in to post comments)

Cross-site scripting vulnerability in Konqueror for KDE 3.0.3

Posted Sep 19, 2002 7:59 UTC (Thu) by dannys (guest, #3651) [Link]

It should be noted that this also affects KDE 2.2.2, which is what the DSA listed above was talking about. 3.0.3a packages, which fix the vulnerability, are available from <a href="http://davidpashley.com/debian-kde/faq.html">the usual place</a>.

Cross-site scripting vulnerability in Konqueror for KDE 3.0.3

Posted Sep 19, 2002 8:00 UTC (Thu) by dannys (guest, #3651) [Link]

Agh, forgot to select HTML. I'm sure you can figure out <a/> syntax, tho. :)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds