KDE Konqueror Address Bar URI Spoofing Vulnerability
BID:24912
Info
KDE Konqueror Address Bar URI Spoofing Vulnerability
| Bugtraq ID: | 24912 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3820 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2007 12:00AM |
| Updated: | May 12 2015 07:49PM |
| Credit: | Robert Swiecki is credited with the discovery of this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Slackware Linux 12.0 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux Desktop version 4 Redhat Enterprise Linux 5 Server Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 KDE Konqueror 3.5.7 |
| Not Vulnerable: | |
Discussion
KDE Konqueror Address Bar URI Spoofing Vulnerability
KDE Konqueror is affected by a URI-spoofing vulnerability because it fails to adequately handle user-supplied data.
An attacker may leverage this issue by padding the URI and inserting arbitrary content to spoof the source URI of a file presented to an unsuspecting user. This may lead to a false sense of trust because the victim may be presented with a source URI of a trusted site while interacting with the attacker's malicious site.
Konqueror 3.5.7 is vulnerable; other versions may also be affected.
NOTE: This issue also affects the Opera browser. This BID originally tracked the issue for both products but has been split into two separate BIDs. The issue affecting Opera is now being tracked as BID 24917.
KDE Konqueror is affected by a URI-spoofing vulnerability because it fails to adequately handle user-supplied data.
An attacker may leverage this issue by padding the URI and inserting arbitrary content to spoof the source URI of a file presented to an unsuspecting user. This may lead to a false sense of trust because the victim may be presented with a source URI of a trusted site while interacting with the attacker's malicious site.
Konqueror 3.5.7 is vulnerable; other versions may also be affected.
NOTE: This issue also affects the Opera browser. This BID originally tracked the issue for both products but has been split into two separate BIDs. The issue affecting Opera is now being tracked as BID 24917.
Exploit / POC
KDE Konqueror Address Bar URI Spoofing Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web document.
The following example exploit is available:
http://alt.swiecki.net/oper1.html
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web document.
The following example exploit is available:
http://alt.swiecki.net/oper1.html
Solution / Fix
KDE Konqueror Address Bar URI Spoofing Vulnerability
Solution:
The vendor released updates and an advisory to address this issue. Please see the references for more information.
Slackware Linux 12.0
KDE Konqueror 3.5.7
Solution:
The vendor released updates and an advisory to address this issue. Please see the references for more information.
Slackware Linux 12.0
-
Slackware kdebase-3.5.7-i486-3_slack12.0.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/ kdebase-3.5.7-i486-3_slack12.0.tgz -
Slackware kdelibs-3.5.7-i486-3_slack12.0.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/ kdelibs-3.5.7-i486-3_slack12.0.tgz
KDE Konqueror 3.5.7
-
KDE post-3.5.7-kdebase-konqueror.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.5.7-kdebase-konquero r.diff -
KDE post-3.5.7-kdelibs-kdecore.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.5.7-kdelibs-kdecore. diff
References
KDE Konqueror Address Bar URI Spoofing Vulnerability
References:
References:
- Diff of /branches/KDE/3.5/kdebase/konqueror/konq_combo.cc (KDE)
- Konqueror Homepage (KDE)
- Konqueror: URL address bar spoofing vulnerabilities ([email protected])
- Opera/Konqueror: data: URL scheme address bar spoofing (Robert Swiecki)
- Re: Opera/Konqueror: data: URL scheme address bar spoofing (Harri Porten)
- KDE Security Advisory: konqueror address bar spoofing (KDE)
- RHSA-2007:0905-4 Moderate: kdebase security update (Red Hat)