KDE Konqueror KHTML Library Title Cross Site Scripting Vulnerability
BID:22428
Info
KDE Konqueror KHTML Library Title Cross Site Scripting Vulnerability
| Bugtraq ID: | 22428 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0478 CVE-2007-0537 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2007 12:00AM |
| Updated: | Mar 19 2015 09:23AM |
| Credit: | Jose Avila is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 10.0.0 x64 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux FUJI Turbolinux Turbolinux 10 F... Turbolinux Home Turbolinux FUJI 0 SuSE SUSE Linux Enterprise Server SDK 9 SuSE SUSE Linux Enterprise Server 9 SP3 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10 SuSE Linux Professional 10.2 x86_64 SuSE Linux Personal 10.2 x86_64 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. SUSE CORE 9 for x86 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Office Server S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Openexchange Server S.u.S.E. Linux Office Server S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Desktop 1.0 S.u.S.E. Linux Desktop 10 S.u.S.E. Linux Database Server 0 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc rPath rPath Linux 1 Pardus Linux 2007.1 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 KDE Libkhtml 4.2 KDE Konqueror 3.5.2 KDE Konqueror 3.5.1 KDE Konqueror 3.3.2 KDE Konqueror 3.3.1 KDE Konqueror 3.3 KDE Konqueror 3.2.3 KDE Konqueror 3.2.2 -6 KDE Konqueror 3.2.1 KDE Konqueror 3.1.5 KDE Konqueror 3.1.4 KDE Konqueror 3.1.3 KDE Konqueror 3.1.2 KDE Konqueror 3.1.1 KDE Konqueror 3.1 KDE Konqueror 3.0.5 b KDE Konqueror 3.0.5 KDE Konqueror 3.0.3 KDE Konqueror 3.0.2 KDE Konqueror 3.0.1 KDE Konqueror 3.0 KDE Konqueror 2.2.2 KDE Konqueror 2.2.1 KDE Konqueror 2.1.2 KDE Konqueror 2.1.1 KDE kdelibs 3.5.4 KDE kdelibs 3.5.2 KDE kdelibs 3.4.3 KDE kdelibs 3.4.2 KDE kdelibs 3.4 KDE kdelibs 3.3.2 KDE kdelibs 3.3.1 KDE kdelibs 3.3 KDE kdelibs 3.2.2 KDE kdelibs 3.2.1 KDE kdelibs 3.2 KDE kdelibs 3.1.5 KDE kdelibs 3.1.4 KDE kdelibs 3.1.3 KDE kdelibs 3.1.2 KDE kdelibs 3.1.1 KDE kdelibs 3.1 KDE kdelibs 3.0 KDE kdelibs 2.1.2 KDE kdelibs 2.1.1 KDE kdelibs 2.1 KDE kdelibs 2.0.1 KDE kdelibs 2.0 KDE KDE 3.5.6 KDE KDE 3.5.5 KDE KDE 3.5.4 KDE KDE 3.5.3 KDE KDE 3.5.2 KDE KDE 3.5.1 KDE KDE 3.5 KDE KDE 3.4.3 KDE KDE 3.4.2 KDE KDE 3.4.1 KDE KDE 3.4 KDE KDE 3.3.2 KDE KDE 3.3.1 KDE KDE 3.3 KDE KDE 3.2.3 KDE KDE 3.2.2 KDE KDE 3.2.1 KDE KDE 3.2 KDE KDE 3.1.5 KDE KDE 3.1.4 KDE KDE 3.1.3 KDE KDE 3.1.2 KDE KDE 3.1.1 a KDE KDE 3.1.1 KDE KDE 3.1 KDE KDE 3.0.5 b KDE KDE 3.0.5 a KDE KDE 3.0.5 KDE KDE 3.0.4 KDE KDE 3.0.3 a KDE KDE 3.0.3 KDE KDE 3.0.2 KDE KDE 3.0.1 KDE KDE 3.0 KDE KDE 2.2.2 KDE KDE 2.2.1 KDE KDE 2.2 KDE KDE 2.1.2 KDE KDE 2.1.1 KDE KDE 2.1 KDE KDE 2.0.1 KDE KDE 2.0 BETA KDE KDE 2.0 KDE KDE 1.2 KDE KDE 1.1.2 KDE KDE 1.1.1 KDE KDE 1.1 Gentoo Linux Apple Safari RSS 2.0 pre-release Apple Safari 2.0.4 Apple Safari 2.0.3 Apple Safari 2.0.2 Apple Safari 2.0.1 Apple Safari 1.3.1 Apple Safari 1.3 Apple Safari 1.2.3 Apple Safari 1.2.2 Apple Safari 1.2.1 Apple Safari 1.2 Apple Safari 1.1 Apple Safari 1.0 Apple Safari Beta 2 Apple Mobile Safari 0 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.3.9 Apple Mac OS X Server 10.3.8 Apple Mac OS X Server 10.3.7 Apple Mac OS X Server 10.3.6 Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.3.3 Apple Mac OS X Server 10.3.2 Apple Mac OS X Server 10.3.1 Apple Mac OS X Server 10.3 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.3.9 Apple Mac OS X 10.3.8 Apple Mac OS X 10.3.7 Apple Mac OS X 10.3.6 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.3.3 Apple Mac OS X 10.3.2 Apple Mac OS X 10.3.1 Apple Mac OS X 10.3 |
| Not Vulnerable: | |
Discussion
KDE Konqueror KHTML Library Title Cross Site Scripting Vulnerability
Konquerer is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.
Exploiting this issue may help the attacker steal cookie-based authentication credentials and launch other attacks.
All versions of KDE up to and including KDE 3.5.6 are vulnerable to this issue. Apple Safari web browser is also vulnerable to this issue.
Konquerer is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.
Exploiting this issue may help the attacker steal cookie-based authentication credentials and launch other attacks.
All versions of KDE up to and including KDE 3.5.6 are vulnerable to this issue. Apple Safari web browser is also vulnerable to this issue.
Exploit / POC
Solution / Fix
KDE Konqueror KHTML Library Title Cross Site Scripting Vulnerability
Solution:
The vendor has released an updated version that addresses this vulnerability. Please see the references for more information.
Apple Mac OS X Server 10.3.9
Apple Mac OS X 10.4.10
KDE kdelibs 3.1.3
KDE kdelibs 3.1.5
KDE kdelibs 3.4.2
Solution:
The vendor has released an updated version that addresses this vulnerability. Please see the references for more information.
Apple Mac OS X Server 10.3.9
-
Apple SecUpdSrvr2007-007Pan.dmg For Mac OS X Server v10.3.9
http://www.apple.com/support/downloads/
Apple Mac OS X 10.4.10
-
Apple SecUpd2007-007Ti.dmg For Mac OS X v10.4.10 (PowerPC)
http://www.apple.com/support/downloads/ -
Apple SecUpd2007-007Univ.dmg For Mac OS X v10.4.10 (Universal)
http://www.apple.com/support/downloads/
KDE kdelibs 3.1.3
-
Turbolinux kdelibs-3.1.5-22.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/kdelibs-3.1.5-22.i586.rpm
KDE kdelibs 3.1.5
-
Turbolinux kdelibs-3.1.5-22.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/kdelibs-3.1.5-22.i586.rpm -
Turbolinux kdelibs-3.1.5-22.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/x64/Server/10/upd ates/RPMS/kdelibs-devel-3.1.5-22.x86_64.rpm -
Turbolinux kdelibs-3.1.5-22.x86_64.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/x64/Server/10/upd ates/RPMS/kdelibs-3.1.5-22.x86_64.rpm -
Turbolinux kdelibs-devel-3.1.5-22.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/x64/Server/10/upd ates/RPMS/kdelibs-devel-3.1.5-22.x86_64.rpm -
Turbolinux kdelibs-devel-3.1.5-22.x86_64.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/x64/Server/10/upd ates/RPMS/kdelibs-devel-3.1.5-22.x86_64.rpm
KDE kdelibs 3.4.2
-
Turbolinux kdelibs-3.4.2-22.i686.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/ -
Turbolinux kdelibs-devel-3.4.2-22.i686.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/
References
KDE Konqueror KHTML Library Title Cross Site Scripting Vulnerability
References:
References:
- KDE Home Page (KDE)
- Konqueror Homepage (Konqueror)
- Re: Safari Improperly Parses HTML Documents & BlogSpot XSS vulnerability (Robert Tasarz)
- Safari Homepage (Apple)
- KDE Security Advisory: khtml/konqueror title XSS vulnerability (KDE)