多个供应商的互联网浏览器的cookie路径参数权限绕过漏洞

漏洞信息详情

多个供应商的互联网浏览器的cookie路径参数权限绕过漏洞

漏洞简介

KDE 3.1.3及其早期版本中的Konqueror存在漏洞。远程攻击者可以通过URL中\”\\%2e\\%2e\”(编码的点点)的目录遍历序列来绕开web应用上预期的cookie访问权限,该漏洞导致Konqueror发送指定的URL子集以外的cookie,例如:与目标应用程序运行在同一服务器上的易受攻击的应用程序。

漏洞公告

RedHat has released advisories RHSA-2004:075-01 and RHSA-2004:074-06 to address this issue in various Red Hat Linux operating systems. Please see the referenced advisories for more information.
Mandrake has released an advisory MDKSA-2004:022 to address this issue. Please see the referenced advisory for more information.
Debian has released an advisory DSA 459-1 to address this issue. Please see the referenced advisory for more information.
SGI ProPack Patch 10062 is available for kdelibs. Please see advisory 20040303-01-U for further details.
RedHat kdelibs-devel-3.1-10.i386.rpm

RedHat kdelibs-3.1-10.i386.rpm

SGI ProPack 2.3

SGI ProPack 2.4

参考网址

来源: REDHAT
名称: RHSA-2004:074
链接:http://www.redhat.com/support/errata/RHSA-2004-074.html

来源: DEBIAN
名称: DSA-459
链接:http://www.debian.org/security/2004/dsa-459

来源: FULLDISC
名称: 20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html

来源: VULNWATCH
名称: 20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue
链接:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html

来源: MANDRAKE
名称: MDKSA-2004:022
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2004:022

来源: US Government Resource: oval:org.mitre.oval:def:823
名称: oval:org.mitre.oval:def:823
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:823

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享