Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a users HTTP session.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Konqueror | Kde | 3.0 (including) | 3.0 (including) |
Konqueror | Kde | 3.0.1 (including) | 3.0.1 (including) |
Konqueror | Kde | 3.0.2 (including) | 3.0.2 (including) |
Konqueror | Kde | 3.0.3 (including) | 3.0.3 (including) |
Konqueror | Kde | 3.0.5 (including) | 3.0.5 (including) |
Konqueror | Kde | 3.0.5b (including) | 3.0.5b (including) |
Konqueror | Kde | 3.1 (including) | 3.1 (including) |
Konqueror | Kde | 3.1.1 (including) | 3.1.1 (including) |
Konqueror | Kde | 3.1.2 (including) | 3.1.2 (including) |
Konqueror | Kde | 3.1.3 (including) | 3.1.3 (including) |
Konqueror | Kde | 3.1.5 (including) | 3.1.5 (including) |
Konqueror | Kde | 3.2.1 (including) | 3.2.1 (including) |
Konqueror | Kde | 3.2.3 (including) | 3.2.3 (including) |
Red Hat Enterprise Linux 3 | RedHat | kdebase-6:3.1.3-5.4 | * |
Red Hat Enterprise Linux 3 | RedHat | kdelibs-6:3.1.3-6.6 | * |