Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.
Link | Tags |
---|---|
http://www.redhat.com/support/errata/RHSA-2005-065.html | patch vendor advisory |
http://marc.info/?l=bugtraq&m=110356286722875&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/18596 | vdb entry |
http://www.heise.de/security/dienste/browsercheck/tests/java.shtml | vendor advisory |
http://www.gentoo.org/security/en/glsa/glsa-200501-16.xml | patch vendor advisory |
http://secunia.com/advisories/13586 | third party advisory patch vendor advisory |
http://www.mandriva.com/security/advisories?name=MDKSA-2004:154 | vendor advisory |
http://www.kde.org/info/security/advisory-20041220-1.txt | patch vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10173 | vdb entry signature |
http://www.kb.cert.org/vuls/id/420222 | us government resource third party advisory patch |