CVE-2003-0459

5 documents5 sources
Severity
5.0MEDIUM
EPSS
1.5%
top 18.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 27
Latest updateApr 29

Description

KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages8 packages

NVDkde/konqueror10 versions+9
NVDredhat/kdebase3.0.3-13
NVDredhat/kdelibs4 versions+3
NVDredhat/kdelibs_devel5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pfc7-m6xf-fmg6: KDE Konqueror for KDE 32022-04-29
CVEList
CVE-2003-0459: KDE Konqueror for KDE 32003-08-01

📋Vendor Advisories

1
Red Hat
security flaw2003-07-29

💬Community

1
Bugzilla
CVE-2003-0459 security flaw2018-08-16
CVE-2003-0459 (MEDIUM CVSS 5) | KDE Konqueror for KDE 3.1.2 and ear | cvebase.io