Search

published date: August 27, 2003

CVE-2003-0459 : KDE Konqueror for KDE...

Description

KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.

Product(s):

  • KDE Konqueror 2.1.1
  • KDE Konqueror 2.2.2
  • KDE Konqueror 3.0.1
  • KDE Konqueror 3.0.2
  • KDE Konqueror 3.0.3
  • KDE Konqueror 3.0.5

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2003-0459, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2003-0459 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?