Back to search
CVE-2003-0459
Published: Aug 1, 2003
Modified: Aug 8, 2024
PUBLISHED
Description
KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20030729 KDE Security Advisory: Konqueror Referrer Authentication Leak
mailing-list
x_refsource_FULLDISC
http://www.kde.org/info/security/advisory-20030729-1.txt
x_refsource_CONFIRM
CLA-2003:747
vendor-advisory
x_refsource_CONECTIVA
DSA-361
vendor-advisory
x_refsource_DEBIAN
oval:org.mitre.oval:def:411
vdb-entry
signature
x_refsource_OVAL
20030802 [slackware-security] KDE packages updated (SSA:2003-213-01)
mailing-list
x_refsource_BUGTRAQ
RHSA-2003:236
vendor-advisory
x_refsource_REDHAT
RHSA-2003:235
vendor-advisory
x_refsource_REDHAT
TLSA-2003-45
vendor-advisory
x_refsource_TURBO
MDKSA-2003:079
vendor-advisory
x_refsource_MANDRAKE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now