KDE Konqueror SetInterval Function Address Bar URI Spoofing Vulnerability
BID:25219
Info
KDE Konqueror SetInterval Function Address Bar URI Spoofing Vulnerability
| Bugtraq ID: | 25219 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-4224 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 07 2007 12:00AM |
| Updated: | Oct 24 2007 04:36PM |
| Credit: | Robert Swiecki is credited with the discovery of this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SuSE Linux 10.1 SuSE Linux 10.0 Slackware Linux 12.0 S.u.S.E. openSUSE 10.3 rPath rPath Linux 1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 KDE Konqueror 3.5.7 KDE Konqueror 3.5.5 |
| Not Vulnerable: | |
Discussion
KDE Konqueror SetInterval Function Address Bar URI Spoofing Vulnerability
KDE Konqueror is affected by a URI-spoofing vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to display arbitrary content while displaying the URL of a trusted website in the address bar. This may lead to a false sense of trust because the victim may be presented with a source URI of a trusted site while interacting with the attacker's malicious site.
Konqueror 3.5.7 is vulnerable; other versions may also be affected.
KDE Konqueror is affected by a URI-spoofing vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to display arbitrary content while displaying the URL of a trusted website in the address bar. This may lead to a false sense of trust because the victim may be presented with a source URI of a trusted site while interacting with the attacker's malicious site.
Konqueror 3.5.7 is vulnerable; other versions may also be affected.
Exploit / POC
KDE Konqueror SetInterval Function Address Bar URI Spoofing Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web document.
The following example exploit is available:
http://alt.swiecki.net/konq2.html
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web document.
The following example exploit is available:
http://alt.swiecki.net/konq2.html
Solution / Fix
KDE Konqueror SetInterval Function Address Bar URI Spoofing Vulnerability
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Slackware Linux 12.0
KDE Konqueror 3.5.7
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Slackware Linux 12.0
-
Slackware kdebase-3.5.7-i486-3_slack12.0.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/ kdebase-3.5.7-i486-3_slack12.0.tgz -
Slackware kdelibs-3.5.7-i486-3_slack12.0.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/ kdelibs-3.5.7-i486-3_slack12.0.tgz
KDE Konqueror 3.5.7
-
KDE post-3.5.7-kdebase-konqueror.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.5.7-kdebase-konquero r.diff -
KDE post-3.5.7-kdelibs-kdecore.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.5.7-kdelibs-kdecore. diff
References
KDE Konqueror SetInterval Function Address Bar URI Spoofing Vulnerability
References:
References:
- Konqueror Homepage (KDE)
- Konqueror: URL address bar spoofing vulnerabilities ([email protected])
- Re: [Full-disclosure] Konqueror: URL address bar spoofing vulnerabilities ([email protected])
- Re: [Full-disclosure] Konqueror: URL address bar spoofing vulnerabilities ([email protected])
- Re: Konqueror: URL address bar spoofing vulnerabilities ([email protected])
- Re: Konqueror: URL address bar spoofing vulnerabilities ([email protected])
- KDE Security Advisory: konqueror address bar spoofing (KDE)
- RHSA-2007:0905-4 Moderate: kdebase security update (Red Hat)