CVE-2003-0459: Medium severity KDE Konqueror vulnerability
KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0459?
CVE-2003-0459 has a moderate severity rating due to the potential for exposing authentication credentials in HTTP Referer headers.
How do I fix CVE-2003-0459?
To fix CVE-2003-0459, users should upgrade to a patched version of KDE Konqueror that does not expose authentication information.
Which versions of KDE Konqueror are affected by CVE-2003-0459?
CVE-2003-0459 affects KDE Konqueror versions 3.1.2 and earlier.
What type of vulnerability is CVE-2003-0459?
CVE-2003-0459 is an information disclosure vulnerability related to the handling of authentication credentials.
Can CVE-2003-0459 be exploited remotely?
Yes, CVE-2003-0459 can be exploited by remote web sites to steal credentials from users visiting linked pages.