Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=110356286722875&w=2 | |
http://secunia.com/advisories/13586 | Patch Vendor Advisory |
http://www.gentoo.org/security/en/glsa/glsa-200501-16.xml | Patch Vendor Advisory |
http://www.heise.de/security/dienste/browsercheck/tests/java.shtml | Vendor Advisory |
http://www.kb.cert.org/vuls/id/420222 | Patch Third Party Advisory US Government Resource |
http://www.kde.org/info/security/advisory-20041220-1.txt | Patch Vendor Advisory |
http://www.mandriva.com/security/advisories?name=MDKSA-2004:154 | |
http://www.redhat.com/support/errata/RHSA-2005-065.html | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/18596 | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10173 |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2004-12-15 05:00
Updated : 2024-02-28 10:24
NVD link : CVE-2004-1145
Mitre link : CVE-2004-1145
CVE.ORG link : CVE-2004-1145
JSON object : View
Products Affected
redhat
- enterprise_linux
- enterprise_linux_desktop
- linux_advanced_workstation
altlinux
- alt_linux
suse
- suse_linux
conectiva
- linux
sgi
- propack
ethereal_group
- ethereal
debian
- debian_linux
CWE