CVE-2004-0411: Input Validation
The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0411?
CVE-2004-0411 has been classified as a medium severity vulnerability due to its potential to allow remote attackers to manipulate options in vulnerable programs.
How do I fix CVE-2004-0411?
To fix CVE-2004-0411, you should update Konqueror to a version later than 3.2.2 where the vulnerability has been addressed.
Which versions of Konqueror are affected by CVE-2004-0411?
CVE-2004-0411 affects Konqueror versions 3.2.2 and earlier.
What types of URIs are impacted by CVE-2004-0411?
CVE-2004-0411 impacts telnet, rlogin, ssh, and mailto URIs in Konqueror.
Can CVE-2004-0411 lead to arbitrary code execution?
Yes, CVE-2004-0411 can potentially allow remote attackers to execute arbitrary commands through manipulated options in affected URI handlers.