TUCoPS :: Linux :: Debian :: dsa-1671.txt

konqueror cross site scripting - Debian Security Advisory DSA 167-1

Debian Security Advisory DSA 167-1 Martin Schulze 
September 16th, 2002 
Package : Konquerer 
Vulnerability : cross site scripting 
Problem-Type : remote 
Debian-specific: no 
Upstream URL : 

A cross site scripting problem has been discovered in Konquerer, a 
famous browser for KDE and other programs using KHTML. The KDE team 
reports that Konqueror's cross site scripting protection fails to 
initialize the domains on sub-(i)frames correctly. As a result, 
Javascript is able to access any foreign subframe which is defined in 
the HTML source. Users of Konqueror and other KDE software that uses 
the KHTML rendering engine may become victim of a cookie stealing and 
other cross site scripting attacks. 

This problem has been fixed in version 2.2.2-13.woody.3 for the 
current stable distribution (woody) and in version 2.2.2-14 for the 
unstable distribution (sid). The old stable distribution (potato) is 
not affected since it didn't ship KDE. 

We recommend that you upgrade your kdelibs package and restart 

wget url 
        will fetch the file for you 
dpkg -i file.deb 
        will install the referenced file. 

If you are using the apt-get package manager, use the line for 
sources.list as given below: 

apt-get update 
        will update the internal database 
apt-get upgrade 
        will install corrected packages 

You may use an automated update by adding the resources from the 
footer to the proper configuration. 

Debian GNU/Linux 3.0 alias woody 
- -------------------------------- 

  Please note that the source packages mentioned above produce more 
  binary packages than the ones listed above. They are not relevant 
  for the fixed problems, though. 

  These files will probably be moved into the stable distribution on 
  its next revision. 

For apt-get: deb stable/updates main 
For dpkg-ftp: dists/stable/updates/main 
Mailing list: 
Package info: `apt-cache show <pkg>' and> 

