CVE-2004-1165: High severity kde konqueror vulnerability
Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1165?
CVE-2004-1165 has a moderate severity level as it allows remote execution of arbitrary FTP commands.
How do I fix CVE-2004-1165?
To fix CVE-2004-1165, ensure that you upgrade to a patched version of the affected KDE kdelibs or Konqueror software.
Which versions are affected by CVE-2004-1165?
CVE-2004-1165 affects KDE kdelibs versions 3.1 through 3.2.2 and Konqueror version 3.3.1.
What type of attack does CVE-2004-1165 allow?
CVE-2004-1165 allows attackers to execute arbitrary FTP commands via specially crafted FTP URLs.
Is CVE-2004-1165 a local or remote vulnerability?
CVE-2004-1165 is a remote vulnerability that can be exploited without local access.