CVE-2003-0592: High severity KDE Konqueror vulnerability
Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0592?
CVE-2003-0592 is considered a moderate severity vulnerability due to its ability to allow unauthorized cookie access.
How do I fix CVE-2003-0592?
To fix CVE-2003-0592, update your KDE Konqueror to a version later than 3.1.3 which addresses this vulnerability.
What versions of Konqueror are affected by CVE-2003-0592?
CVE-2003-0592 affects KDE Konqueror versions 3.1.3 and earlier, as well as several earlier versions like 2.1.1 and 3.1.2.
What is the impact of CVE-2003-0592?
The impact of CVE-2003-0592 is that it allows remote attackers to bypass cookie access restrictions, potentially compromising user sessions.
Which software is vulnerable to CVE-2003-0592?
The vulnerable software for CVE-2003-0592 includes various versions of KDE Konqueror up to 3.1.3.