漏洞信息详情
多个供应商的互联网浏览器的cookie路径参数权限绕过漏洞
- CNNVD编号:CNNVD-200404-035
- 危害等级: 高危
- CVE编号:
CVE-2003-0593
- 漏洞类型:
路径遍历
- 发布时间:
2004-04-15
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
opera_software - 漏洞来源:
Discovery is credi… -
漏洞简介
Opera存在漏洞。远程攻击者可以通过URL中\”\\%2e\\%2e\”(编码的点点)的目录遍历序列来绕开web应用上预期的cookie访问权限,该漏洞导致Opera发送指定的URL子集以外的cookie,例如:与目标应用程序运行在同一服务器上的易受攻击的应用程序。
漏洞公告
RedHat has released advisories RHSA-2004:075-01 and RHSA-2004:074-06 to address this issue in various Red Hat Linux operating systems. Please see the referenced advisories for more information.
Mandrake has released an advisory MDKSA-2004:022 to address this issue. Please see the referenced advisory for more information.
Debian has released an advisory DSA 459-1 to address this issue. Please see the referenced advisory for more information.
SGI ProPack Patch 10062 is available for kdelibs. Please see advisory 20040303-01-U for further details.
RedHat kdelibs-devel-3.1-10.i386.rpm
-
RedHat kdelibs-devel-3.1-13.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/kdelibs-devel-3.1-13.i386.rpm
RedHat kdelibs-3.1-10.i386.rpm
-
RedHat kdelibs-3.1-13.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/kdelibs-3.1-13.i386.rpm
SGI ProPack 2.3
-
SGI patch10062.tar.gz
ftp://patches.sgi.com/support/free/security/patches/ProPack/2.3/patch1
0062.tar.gz
SGI ProPack 2.4
-
SGI patch10062.tar.gz
ftp://patches.sgi.com/support/free/security/patches/ProPack/2.4/patch1
0062.tar.gz
参考网址
来源: FULLDISC
名称: 20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html
来源: VULNWATCH
名称: 20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue
链接:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html