CVE-2004-1145: Medium severity ethereal group ethereal vulnerability
Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1145?
CVE-2004-1145 is considered a high severity vulnerability due to its potential to allow unauthorized access to restricted Java classes.
How do I fix CVE-2004-1145?
To fix CVE-2004-1145, you should upgrade to a version of Konqueror that is later than KDE 3.3.1, which contains the necessary patches.
What systems are affected by CVE-2004-1145?
CVE-2004-1145 affects Konqueror in KDE versions up to and including 3.3.1 as well as various distributions that include these versions.
Can CVE-2004-1145 allow data leakage?
Yes, CVE-2004-1145 can allow remote attackers to bypass sandbox restrictions and access sensitive data.
Is CVE-2004-1145 specific to certain Java implementations?
CVE-2004-1145 specifically relates to vulnerabilities within Konqueror's handling of JavaScript and Java classes, not specific Java implementations.