A couple of KDE security advisories
[Posted September 11, 2002 by corbet]
The KDE project has issued a couple of security advisories:
- This one describes a cross-site
scripting vulnerability in Konqueror (and any other application which
uses the KHTML renderer). Javascript code running in one frame can
access other frames which should be inaccessible. This problem is
fixed in kdelibs 3.0.3a.
- The second is for a secure cookie
problem in Konqueror. The "secure" flag in cookies is not recognized,
with the result that "secure" cookes can be transmitted over
unencrypted connections. KDE 3.0.3 fixes the problem.
We will, of course, pass on distributor updates as we receive them.
(
Log in to post comments)