|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
[SA13717] Konqueror Download Dialog Source Spoofing
From: Secunia Security Advisories (sec-adv
secunia.com)
Date: Thu Mar 17 2005 - 06:21:42 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
----------------------------------------------------------------------
Want a new IT Security job?
Vacant positions at Secunia:
http://secunia.com/secunia_vacancies/
----------------------------------------------------------------------
TITLE:
Konqueror Download Dialog Source Spoofing
SECUNIA ADVISORY ID:
SA13717
VERIFY ADVISORY:
http://secunia.com/advisories/13717/
CRITICAL:
Less critical
IMPACT:
Spoofing
WHERE:
From remote
SOFTWARE:
Konqueror 3.x
http://secunia.com/product/3166/
DESCRIPTION:
Secunia Research has discovered a vulnerability in Konqueror, which
can be exploited by malicious people to spoof the source displayed in
the Download Dialog box.
The problem is that long sub-domains and paths aren't displayed
correctly, which therefore can be exploited to obfuscate what is
being displayed in the source field and title bar of the Download
Dialog box.
The vulnerability has been confirmed in Konqueror versions 3.2.2 and
3.3.1. Other versions may also be affected.
SOLUTION:
Do not follow download links from untrusted sources.
PROVIDED AND/OR DISCOVERED BY:
Jakob Balle, Secunia Research.
ORIGINAL ADVISORY:
Secunia Research:
http://secunia.com/secunia_research/2005-1/advisory/
OTHER REFERENCES:
KDE Bug Report:
http://bugs.kde.org/show_bug.cgi?id=96297
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
----------------------------------------------------------------------
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]