CVE-2007-4224 Information

Description

KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar by calling setInterval with a small interval and changing the window.location property.

Reference

http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065101.html http://lists.opensuse.org/opensuse-security-announce/2007-10/msg00006.html http://secunia.com/advisories/26351 http://secunia.com/advisories/26612 http://secunia.com/advisories/26690 http://secunia.com/advisories/26720 http://secunia.com/advisories/27089 http://secunia.com/advisories/27090 http://secunia.com/advisories/27096 http://secunia.com/advisories/27106 http://secunia.com/advisories/27108 http://secunia.com/advisories/27271 http://securityreason.com/securityalert/2982 http://securitytracker.com/id?1018579 http://www.kde.org/info/security/advisory-20070816-1.txt http://www.mandriva.com/security/advisories?name=MDKSA-2007:176 http://www.redhat.com/support/errata/RHSA-2007-0905.html http://www.redhat.com/support/errata/RHSA-2007-0909.html http://www.securityfocus.com/archive/1/475689/100/0/threaded http://www.securityfocus.com/archive/1/475730/100/0/threaded http://www.securityfocus.com/archive/1/475731/100/0/threaded http://www.securityfocus.com/archive/1/475763/100/0/threaded http://www.securityfocus.com/bid/25219 http://www.ubuntu.com/usn/usn-502-1 http://www.vupen.com/english/advisories/2007/2807 https://exchange.xforce.ibmcloud.com/vulnerabilities/35828 https://issues.rpath.com/browse/RPL-1615 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A9879 https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00022.html https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00085.html

Share on: