SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#420222

Konqueror fails to restrict access to Java classes

Overview

The Konqueror web browser may allow Java applets and JavaScripts to bypass the Java security settings and access restricted Java classes. Exploitation may allow a remote attacker to read and write arbitrary files on a vulnerable system.

I. Description

Konqueror is a web browser and file manager for the K Desktop Environment (KDE). A flaw in Konqueror may allow Java applets and JavaScripts to bypass the Java security settings and access restricted Java classes. Once the security restrictions are bypassed, the malicious applet or script may be able to access and manipulate system resources.

For more information on the Java security model see Sun's Java documentation, particularly the Applet Security FAQ referenced above. Microsoft provides similar documentation in its Java Security Overview and a corresponding FAQ.

Note that Java must be enabled in Konqueror to exploit this vulnerability with a Java applet. For exploitation via JavaScript, active scripting must be enabled.

II. Impact

By enticing a user to view and execute a malicious Java applet or JavaScript , a remote attacker may be able to read and write arbitrary files with the privileges of the browser process.

III. Solution

Upgrade


Update to Konqueror version 3.3.2.

Apply Patch

A patch for Konqueror 3.2.3 is available to correct this issue.

Disable Active Scripting and Java

At a minimum, disable Active scripting and Java within the web browser. Instructions for disabling Active scripting and Java can be found in the CERT/CC Malicious Web Scripts FAQ.

Systems Affected

VendorStatusDate NotifiedDate Updated
KDE Desktop Environment ProjectUnknown21-Dec-2004

References


http://www.kde.org/info/security/advisory-20041220-1.txt
http://secunia.com/advisories/13586/
http://xforce.iss.net/xforce/xfdb/18596
http://www.osvdb.org/displayvuln.php?osvdb_id=12512

Credit

This vulnerability was publicly reported by Waldo Bastian.

This document was written by Jeff Gennari.

Other Information

Date Public:2004-12-20
Date First Published:2005-01-05
Date Last Updated:2005-01-14
CERT Advisory: 
CVE-ID(s):CAN-2004-1145
NVD-ID(s):CAN-2004-1145
US-CERT Technical Alerts: 
Metric:3.90
Document Revision:49

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2005 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader