|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2003-0459: security leak in khtml in all releases. | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Adrian Schröter <adrian.schroeter> |
| Component: | Incidents | Assignee: | Adrian Schröter <adrian.schroeter> |
| Status: | RESOLVED DUPLICATE | QA Contact: | Security Team bot <security-team> |
| Severity: | Critical | ||
| Priority: | P3 - Medium | CC: | hmuelle, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | CVE-2003-0459: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) | ||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Attachments: |
putonftp
patchinfo |
||
|
Description
Adrian Schröter
2003-07-16 17:30:22 UTC
Thomas, any news? Hm, I was really not aware of this bug. What is still needed. Putonftp, Patchinfo, Laufzettel, etc. pp.? Created attachment 13957 [details]
putonftp
Created attachment 13958 [details]
patchinfo
Hm, this issue was already handled by me. I found this one ob pama-laufzettel, so I am out of duty. ;-P Date: Wed, 16 Jul 2003 11:38:21 +0200 (CEST) From: Thomas Biege <thomas@suse.de> To: pama-laufzettel@suse.de Subject: [pama-laufzettel] [patch][NR 0360] kdelibs, info leak via referer Subject: [patch][NR 0360] kdelibs, info leak via referer [n] bofh@suse.de notified if critical security-team [n] cto + vp devel notified if critical security-team [y] qa notified security-team [ ] hardware certification notified security-team [ ] patchinfo created+submitted adrian,security-team [ ] putonftp file(s) created+submitted adrian,security-team [ ] patch applied, package checked in adrian,security-team [ ] docs for patchinfo submitted supporters [ ] patchinfo seen on patch-management@. supporters [y] test required security-team ~ [ ] package tested qa-team ~ [ ] patchinfo tested qa-team ~ [ ] YOU update tested int. qa-team ~ [ ] patchinfo approved (qa step) qa-team [ ] patchinfo approved security-team or prod/projmgr [ ] update on maintenance web supporters [ ] customer notified supporters [ ] reference machines updated qa-team [ ] DMZ servers updated bofh@suse.de [ ] Announcement published security-team ETP (Estimated time of publication): KW 31 Bug number: #27976 Severity: critical Description: Konqueror may inadvertently send authentication credentials to websites other than the intended website in clear text via the HTTP-referer header when authentication credentials are passed as part of a URL in the form of http://user:password@host/ Release date from Laufzettel: 21.07.2003 Hits the following platforms (from Laufzetel): SLES8, SLES7, SL8.1, SL8.0 Major security issue - cause of the long delay set from normal to critical not major it hits also all maintained 7.x. I start to work on this now, if not stopped by something else (9.0 related). erm .... the packages in autobuild contains already the patches .... so, I guess we stopped at testing and (re-)writting the patch/putonftp files ... *** This bug has been marked as a duplicate of 42226 *** CVE-2003-0459: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) |