CVE-2004-0867: High severity KDE Konqueror vulnerability
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it was later reported that 2.x is also affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0867?
CVE-2004-0867 is considered a moderate severity vulnerability that could allow session fixation attacks.
How do I fix CVE-2004-0867?
To mitigate CVE-2004-0867, users should update to the latest versions of affected browsers, particularly Mozilla Firefox and KDE Konqueror.
Which software is affected by CVE-2004-0867?
CVE-2004-0867 primarily affects Mozilla Firefox versions prior to 1.0 and several versions of KDE Konqueror.
What type of attack does CVE-2004-0867 enable?
CVE-2004-0867 enables remote attackers to perform session fixation attacks which can hijack a user's HTTP session.
Is CVE-2004-0867 present in newer versions of affected software?
Yes, later reports indicate that Mozilla Firefox 2.x versions are also affected by CVE-2004-0867.