Vulnerability CVE-2003-0459


Published: 2003-08-27   Modified: 2012-02-12

Description:
KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.

Vendor: KDE
Product: Konqueror 
Version:
3.1.2
3.1.1
3.1
3.0.5
3.0.3
3.0.2
3.0.1
3.0
2.2.2
2.1.1
Product: Konqueror embedded 
Version: 0.1;
Vendor: Redhat
Product: Kdelibs devel 
Version:
3.1-10
3.0.3-8
3.0.0-10
2.2-11
2.1.1-5
Product: Kdelibs 
Version:
3.1-10
3.0.0-10
2.2-11
2.1.1-5
Product: Kdebase 
Version: 3.0.3-13;
Product: Analog real-time synthesizer 
Version: 2.2-11; 2.1.1-5;
Product: Kdelibs sound 
Version: 2.2-11; 2.1.1-5;
Product: Kdelibs sound devel 
Version: 2.2-11; 2.1.1-5;

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None

 References:
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000747
http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/007300.html
http://marc.info/?l=bugtraq&m=105986238428061&w=2
http://www.debian.org/security/2003/dsa-361
http://www.kde.org/info/security/advisory-20030729-1.txt
http://www.mandriva.com/security/advisories?name=MDKSA-2003:079
http://www.redhat.com/support/errata/RHSA-2003-235.html
http://www.redhat.com/support/errata/RHSA-2003-236.html
http://www.turbolinux.com/security/TLSA-2003-45.txt
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A411

Related CVE
CVE-2016-10746
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.
CVE-2019-3891
It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use those credentials to modify th...
CVE-2019-3459
A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.
CVE-2019-3845
A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host regi...
CVE-2019-3837
It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unprivileged multi-threaded userspace application calling recvmsg() for the same network socket in parallel executed on ioatdma-enabl...
CVE-2019-3842
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable wh...
CVE-2017-3139
A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.
CVE-2019-3893
In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource. A malicious user with the "delete_compute_resou...

Copyright 2019, cxsecurity.com

 

Back to Top