|
KDE Konqueror Address Bar URI Spoofing Vulnerability
KDE Konqueror is affected by a URI-spoofing vulnerability because it fails to adequately handle user-supplied data. An attacker may leverage this issue by padding the URI and inserting arbitrary content to spoof the source URI of a file presented to an unsuspecting user. This may lead to a false sense of trust because the victim may be presented with a source URI of a trusted site while interacting with the attacker's malicious site. Konqueror 3.5.7 is vulnerable; other versions may also be affected. NOTE: This issue also affects the Opera browser. This BID originally tracked the issue for both products but has been split into two separate BIDs. The issue affecting Opera is now being tracked as BID 24917. |
|
|
Privacy Statement |