CVE-2004-0746: High severity KDE Konqueror vulnerability
Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0746?
CVE-2004-0746 is considered a medium severity vulnerability due to its potential to allow session fixation attacks.
How do I fix CVE-2004-0746?
To fix CVE-2004-0746, update Konqueror to a version later than 3.2.3, which addresses the vulnerability.
What are the affected versions mentioned in CVE-2004-0746?
CVE-2004-0746 affects Konqueror versions 3.2.3 and earlier.
What kind of attack can exploit CVE-2004-0746?
CVE-2004-0746 can be exploited to perform a session fixation attack, allowing attackers to hijack user sessions.
Which platforms are affected by CVE-2004-0746?
CVE-2004-0746 affects various Linux distributions that include vulnerable versions of Konqueror, primarily KDE-based systems.