KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar by calling setInterval with a small interval and changing the window.location property.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Konqueror | Kde | 3.5.7 (including) | 3.5.7 (including) |
Red Hat Enterprise Linux 4 | RedHat | kdebase-6:3.3.1-6.el4 | * |
Red Hat Enterprise Linux 4 | RedHat | kdelibs-6:3.3.1-9.el4 | * |
Red Hat Enterprise Linux 5 | RedHat | kdebase-6:3.5.4-15.el5 | * |
Red Hat Enterprise Linux 5 | RedHat | kdelibs-6:3.5.4-13.el5 | * |
Kdebase | Ubuntu | dapper | * |
Kdebase | Ubuntu | devel | * |
Kdebase | Ubuntu | edgy | * |
Kdebase | Ubuntu | feisty | * |
Kdebase | Ubuntu | upstream | * |