First published: Mon Apr 11 2011(Updated: )
It was reported [1] that Konqueror in KDE 4.4.0 through to and including 4.6.1 is vulnerable to a partially universal XSS in error pages. When Konqueror cannot fetch a requested URL, it renders an error page that contains the given URL. If the URL were to contain JavaScript or HTML code, the code is also rendered which could allow for a user to be tricked into visiting a malicious web site or to provide credentials to an untrusted party. Patches are available for the 4.4, 4.5, and 4.6 branches, linked to from the upstream security advisory. [1] <a href="http://www.kde.org/info/security/advisory-20110411-1.txt">http://www.kde.org/info/security/advisory-20110411-1.txt</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Konqueror | >=4.4.0<=4.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-695398 is considered moderate due to the potential for XSS attacks through error pages.
To fix REDHAT-BUG-695398, upgrade Konqueror to a version later than 4.6.1.
Konqueror versions 4.4.0 through 4.6.1 are affected by REDHAT-BUG-695398.
REDHAT-BUG-695398 is a partial universal Cross-Site Scripting (XSS) vulnerability.
Attackers can exploit REDHAT-BUG-695398 to execute arbitrary JavaScript or HTML code in the user's browser.