KDE Konqueror Remote Window Hijacking Vulnerability
BID:11853
Info
KDE Konqueror Remote Window Hijacking Vulnerability
| Bugtraq ID: | 11853 |
| Class: | Design Error |
| CVE: |
CVE-2004-1158 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2004 12:00AM |
| Updated: | Jul 12 2009 08:07AM |
| Credit: | Discovery of the issue is credited to Secunia Research. |
| Vulnerable: |
SuSE Linux 8.1 SuSE Linux 8.0 i386 SuSE Linux 8.0 SGI ProPack 3.0 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Redhat Fedora Core3 Redhat Fedora Core2 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 KDE Konqueror 3.3.2 KDE Konqueror 3.3.1 KDE Konqueror 3.3 KDE Konqueror 3.2.3 KDE Konqueror 3.2.2 -6 KDE Konqueror 3.2.1 KDE Konqueror 3.1.5 KDE Konqueror 3.1.4 KDE Konqueror 3.1.3 KDE Konqueror 3.1.2 KDE Konqueror 3.1.1 KDE Konqueror 3.1 KDE Konqueror 3.0.5 b KDE Konqueror 3.0.5 KDE Konqueror 3.0.3 KDE Konqueror 3.0.2 KDE Konqueror 3.0.1 KDE Konqueror 3.0 KDE Konqueror 2.2.2 KDE Konqueror 2.2.1 KDE Konqueror 2.1.2 KDE Konqueror 2.1.1 |
| Not Vulnerable: | |
Discussion
KDE Konqueror Remote Window Hijacking Vulnerability
Konqueror is reported prone to a vulnerability that may allow a Web site to hijack the contents of a trusted window. This issue may allow a remote attacker to carry out phishing style attacks.
This issue arises as a user visits a malicious site and follows a link to a trusted site. Once the link to the trusted site is followed, the victim must open a pop up window from the trusted site that can be influenced by the attacker's site.
If successful, the contents of the target site's window can be spoofed resulting in phishing style attacks.
Konqueror 3.2.2-6 is reported vulnerable to this issue, however, it is possible that other versions are affected as well.
Konqueror is reported prone to a vulnerability that may allow a Web site to hijack the contents of a trusted window. This issue may allow a remote attacker to carry out phishing style attacks.
This issue arises as a user visits a malicious site and follows a link to a trusted site. Once the link to the trusted site is followed, the victim must open a pop up window from the trusted site that can be influenced by the attacker's site.
If successful, the contents of the target site's window can be spoofed resulting in phishing style attacks.
Konqueror 3.2.2-6 is reported vulnerable to this issue, however, it is possible that other versions are affected as well.
Exploit / POC
KDE Konqueror Remote Window Hijacking Vulnerability
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_window_injection_vulnerability_test/
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_window_injection_vulnerability_test/
Solution / Fix
KDE Konqueror Remote Window Hijacking Vulnerability
Solution:
KDE has released an advisory with patches for KDE 3.2.3 and 3.3.2. Please see the advisory in Web references for more information.
RedHat has released advisories FEDORA-2004-548, FEDORA-2004-549, FEDORA-2004-550, and FEDORA-2004-551 to address this issue in Fedora Core 2 and 3. Please see the referenced advisories for further information.
Mandrake has released advisory MDKSA-2004:150 and fixes to address this issue. Please see the referenced advisory for further information.
Gentoo has released an advisory to provide updates for this issue. Updates may be applied by running the following commands as the superuser:
(For kdelibs)
emerge --sync
emerge --ask --oneshot --verbose ">=kde-base/kdelibs-3.2.3-r4"
(For kdebase)
emerge --sync
emerge --ask --oneshot --verbose ">=kde-base/kdebase-3.2.3-r3"
SuSE Linux has released a security summary report (SUSE-SR:2005:003) that contains fixes to address this and other vulnerabilities. Customers are advised to peruse the referenced advisory for further information regarding obtaining and applying appropriate updates.
Red Hat has released advisory RHSA-2005:009-19 to address issues in KDE. Please see the advisory in Web references for more information.
SGI has released advisory 20050207-01-U including Patch 10144 that contains updated SGI ProPack 3 Service Pack 4 RPMs for the SGI Altix products. This patch addresses various issues. Please see the referenced advisory for more information.
SGI ProPack 3.0
KDE Konqueror 3.2.3
KDE Konqueror 3.3.2
Solution:
KDE has released an advisory with patches for KDE 3.2.3 and 3.3.2. Please see the advisory in Web references for more information.
RedHat has released advisories FEDORA-2004-548, FEDORA-2004-549, FEDORA-2004-550, and FEDORA-2004-551 to address this issue in Fedora Core 2 and 3. Please see the referenced advisories for further information.
Mandrake has released advisory MDKSA-2004:150 and fixes to address this issue. Please see the referenced advisory for further information.
Gentoo has released an advisory to provide updates for this issue. Updates may be applied by running the following commands as the superuser:
(For kdelibs)
emerge --sync
emerge --ask --oneshot --verbose ">=kde-base/kdelibs-3.2.3-r4"
(For kdebase)
emerge --sync
emerge --ask --oneshot --verbose ">=kde-base/kdebase-3.2.3-r3"
SuSE Linux has released a security summary report (SUSE-SR:2005:003) that contains fixes to address this and other vulnerabilities. Customers are advised to peruse the referenced advisory for further information regarding obtaining and applying appropriate updates.
Red Hat has released advisory RHSA-2005:009-19 to address issues in KDE. Please see the advisory in Web references for more information.
SGI has released advisory 20050207-01-U including Patch 10144 that contains updated SGI ProPack 3 Service Pack 4 RPMs for the SGI Altix products. This patch addresses various issues. Please see the referenced advisory for more information.
SGI ProPack 3.0
-
SGI Patch10144
http://support.sgi.com/
KDE Konqueror 3.2.3
-
KDE post-3.2.3-kdebase-htmlframes2.patch
ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdebase-htmlfram es2.patch -
KDE post-3.2.3-kdelibs-htmlframes2.patch
ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdelibs-htmlfram es2.patch
KDE Konqueror 3.3.2
-
KDE post-3.3.2-kdebase-htmlframes2.patch
ftp://ftp.kde.org/pub/kde/security_patches/post-3.3.2-kdebase-htmlfram es2.patch -
KDE post-3.3.2-kdelibs-htmlframes2.patch
ftp://ftp.kde.org/pub/kde/security_patches/post-3.3.2-kdelibs-htmlfram es2.patch
References
KDE Konqueror Remote Window Hijacking Vulnerability
References:
References:
- KDE Security Advisory: Konqueror Window Injection Vulnerability (KDE)
- Konqueror Homepage (KDE)
- Konqueror Window Injection Vulnerability (Secunia)
- RHSA-2005:009-19 - Updated kdelibs and kdebase packages correct security issues (RedHat)
- KDE Security Advisory: Konqueror Window Injection Vulnerability (Waldo Bastian
)