Description
Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.
Affected products
- altlinux / alt_linux2.3 – 2.3
- altlinux / alt_linux2.3 – 2.3
- conectiva / linux9.0 – 9.0
- conectiva / linux10.0 – 10.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- ethereal_group / ethereal0.9.15 – 0.9.15
- ethereal_group / ethereal0.9.16 – 0.9.16
- ethereal_group / ethereal0.10 – 0.10
- ethereal_group / ethereal0.10.1 – 0.10.1
- ethereal_group / ethereal0.10.2 – 0.10.2
- ethereal_group / ethereal0.10.3 – 0.10.3
- ethereal_group / ethereal0.10.4 – 0.10.4
- ethereal_group / ethereal0.10.5 – 0.10.5
- ethereal_group / ethereal0.10.6 – 0.10.6
- ethereal_group / ethereal0.10.7 – 0.10.7
- ethereal_group / ethereal0.9.14 – 0.9.14
- ethereal_group / ethereal0.9.1 – 0.9.1
- ethereal_group / ethereal0.9.2 – 0.9.2
- ethereal_group / ethereal0.9.3 – 0.9.3
- ethereal_group / ethereal0.9.4 – 0.9.4
- ethereal_group / ethereal0.9.5 – 0.9.5
- ethereal_group / ethereal0.9.6 – 0.9.6
- ethereal_group / ethereal0.9.7 – 0.9.7
- ethereal_group / ethereal0.9.8 – 0.9.8
- ethereal_group / ethereal0.9.9 – 0.9.9
- ethereal_group / ethereal0.9.10 – 0.9.10
- ethereal_group / ethereal0.9.11 – 0.9.11
- ethereal_group / ethereal0.9.12 – 0.9.12
- ethereal_group / ethereal0.9.13 – 0.9.13
- ethereal_group / ethereal0.9 – 0.9
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux_desktop3.0 – 3.0
- RedHat / linux_advanced_workstation2.1 – 2.1
- RedHat / linux_advanced_workstation2.1 – 2.1
- sgi / propack3.0 – 3.0
- SUSE / suse_linux8.0 – 8.0
- SUSE / suse_linux8.0 – 8.0
- SUSE / suse_linux8.1 – 8.1
- SUSE / suse_linux8.2 – 8.2
- SUSE / suse_linux9.0 – 9.0
- SUSE / suse_linux9.0 – 9.0
- SUSE / suse_linux9.1 – 9.1
- SUSE / suse_linux9.2 – 9.2
References
- MISChttp://www.redhat.com/support/errata/RHSA-2005-065.html
- MAILING_LISThttp://marc.info/?l=bugtraq&m=110356286722875&w=2
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/18596
- MISChttp://www.heise.de/security/dienste/browsercheck/tests/java.shtml
- MISChttp://www.gentoo.org/security/en/glsa/glsa-200501-16.xml
- VENDOR_ADVISORYhttp://secunia.com/advisories/13586
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDKSA-2004:154
- MISChttp://www.kde.org/info/security/advisory-20041220-1.txt
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10173
- MISChttp://www.kb.cert.org/vuls/id/420222