CVE-2004-0866: High severity KDE Konqueror vulnerability
Published Sep 16, 2004
·Updated
Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
Affected Software
27 affected components
KDE Konqueror=2.1.1
KDE Konqueror=2.1.2
KDE Konqueror=2.2.1
KDE Konqueror=2.2.2
KDE Konqueror=3.0
KDE Konqueror=3.0.1
KDE Konqueror=3.0.2
KDE Konqueror=3.0.3
KDE Konqueror=3.0.5
KDE Konqueror=3.0.5b
KDE Konqueror=3.1
KDE Konqueror=3.1.1
KDE Konqueror=3.1.2
KDE Konqueror=3.1.3
KDE Konqueror=3.1.4
KDE Konqueror=3.1.5
KDE Konqueror=3.2.1
KDE Konqueror=3.2.3
Microsoft ie=6.0-sp1
Microsoft ie=6.0-sp2
Microsoft Internet Explorer=6.0
Mozilla Firefox=0.9.2
SUSE SuSE Linux=1.0
SUSE SuSE Linux=8
SUSE SuSE Linux=8.1
SUSE SuSE Linux=8.2
SUSE SuSE Linux=9.0
Remediation
Patch Available
Event History
Sep 16, 2004
CVE Published
04:00 AM
Feb 13, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0866?
CVE-2004-0866 has a moderate severity rating due to its potential for session fixation attacks.
2
How do I fix CVE-2004-0866?
To fix CVE-2004-0866, ensure that your web applications implement proper cookie handling to prevent session fixation.
3
Which software is affected by CVE-2004-0866?
CVE-2004-0866 affects Internet Explorer 6.0 and several versions of KDE Konqueror.
4
What type of attack does CVE-2004-0866 enable?
CVE-2004-0866 enables remote attackers to perform session fixation attacks.
5
How can users protect themselves from CVE-2004-0866?
Users can protect themselves by avoiding the use of vulnerable browsers and staying updated with the latest security patches.