Mandrake Linux Security Advisory : konqueror (MDKSA-2007:176)

Medium Nessus Plugin ID 26008

Synopsis

The remote Mandrake Linux host is missing one or more security updates.

Description

konqueror/konq_combo.cc in Konqueror 3.5.7 allows remote attackers to spoof the data: URI scheme in the address bar via a long URI with trailing whitespace, which prevents the beginning of the URI from being displayed. (CVE-2007-3820)

KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar by calling setInterval with a small interval and changing the window.location property. (CVE-2007-4224)

Visual truncation vulnerability in KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar via an http URI with a large amount of whitespace in the user/password portion. (CVE-2007-4225)

Updated packages fix these issues.

Solution

Update the affected packages.

Plugin Details

Severity: Medium

ID: 26008

File Name: mandrake_MDKSA-2007-176.nasl

Version: 1.17

Type: local

Published: 2007/09/07

Updated: 2018/12/05

Dependencies: 12634

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:kdebase, p-cpe:/a:mandriva:linux:kdebase-common, p-cpe:/a:mandriva:linux:kdebase-kate, p-cpe:/a:mandriva:linux:kdebase-kdeprintfax, p-cpe:/a:mandriva:linux:kdebase-kdm, p-cpe:/a:mandriva:linux:kdebase-kmenuedit, p-cpe:/a:mandriva:linux:kdebase-konsole, p-cpe:/a:mandriva:linux:kdebase-nsplugins, p-cpe:/a:mandriva:linux:kdebase-progs, p-cpe:/a:mandriva:linux:kdebase-session-plugins, p-cpe:/a:mandriva:linux:kdelibs-common, p-cpe:/a:mandriva:linux:kdelibs-devel-doc, p-cpe:/a:mandriva:linux:lib64kdebase4, p-cpe:/a:mandriva:linux:lib64kdebase4-devel, p-cpe:/a:mandriva:linux:lib64kdebase4-kate, p-cpe:/a:mandriva:linux:lib64kdebase4-kate-devel, p-cpe:/a:mandriva:linux:lib64kdebase4-kmenuedit, p-cpe:/a:mandriva:linux:lib64kdebase4-konsole, p-cpe:/a:mandriva:linux:lib64kdecore4, p-cpe:/a:mandriva:linux:lib64kdecore4-devel, p-cpe:/a:mandriva:linux:libkdebase4, p-cpe:/a:mandriva:linux:libkdebase4-devel, p-cpe:/a:mandriva:linux:libkdebase4-kate, p-cpe:/a:mandriva:linux:libkdebase4-kate-devel, p-cpe:/a:mandriva:linux:libkdebase4-kmenuedit, p-cpe:/a:mandriva:linux:libkdebase4-konsole, p-cpe:/a:mandriva:linux:libkdecore4, p-cpe:/a:mandriva:linux:libkdecore4-devel, cpe:/o:mandriva:linux:2007, cpe:/o:mandriva:linux:2007.1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2007/09/06

Reference Information

CVE: CVE-2007-3820, CVE-2007-4224, CVE-2007-4225

BID: 24912

MDKSA: 2007:176

CWE: 59