CVE-2005-4684: Medium severity Konqueror vulnerability
Konqueror can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers to trick a user into accepting a cookie for a hostname formed via search-list expansion of the hostname entered by the user, or steal a cookie for an expanded hostname, as demonstrated by an attacker who operates an ap1.com Internet web site to steal cookies associated with an ap1.com.example.com intranet web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4684?
CVE-2005-4684 is classified as a medium severity vulnerability due to its potential to allow remote users to manipulate cookies.
How do I fix CVE-2005-4684?
To fix CVE-2005-4684, ensure that you are using an updated version of KDE Konqueror that addresses this vulnerability.
Which versions of KDE Konqueror are affected by CVE-2005-4684?
CVE-2005-4684 affects multiple versions of KDE Konqueror, specifically version 2.1.1 and later up to 3.3.2.
What types of attacks can exploit CVE-2005-4684?
CVE-2005-4684 can be exploited through cookie manipulation, allowing attackers to create cookies associated with unintended domains.
Who reported CVE-2005-4684?
CVE-2005-4684 was reported in the Fulusdisclosure mailing list and addressed by various security resources in 2005.