From 995f5c074d05537e8d2911e1e13d15b6d9ad031c Mon Sep 17 00:00:00 2001 From: Remko Lodder Date: Wed, 19 Sep 2007 17:06:27 +0000 Subject: Document kdm -- passwordless login vulnerability Document konquerer -- address bar spoofing Inspired by: lofi's cvs commits --- security/vuxml/vuln.xml | 65 +++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 65 insertions(+) (limited to 'security/vuxml/vuln.xml') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 79d342c332b5..76606b77abf2 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -34,6 +34,71 @@ Note: Please add new entries to the beginning of this file. --> + + konquerer -- address bar spoofing + + + kdebase3 + 3.5.7_3 + + + kdelibs3 + 3.5.7_2 + + + + +

The KDE development team reports:

+
+

The Konqueror address bar is vulnerable to spoofing attacks + that are based on embedding white spaces in the url. In addition + the address bar could be tricked to show an URL which it is + intending to visit for a short amount of time instead of the + current URL.

+
+ +
+ + CVE-2007-3820 + CVE-2007-4224 + CVE-2007-4225 + http://www.kde.org/info/security/advisory-20070914-1.txt + + + 2007-09-14 + 2007-09-19 + +
+ + + kdm -- passwordless login vulnerability + + + kdebase3 + 3.5.7_3 + + + + +

The KDE development team reports:

+
+

KDM can be tricked into performing a password-less login + even for accounts with a password set under certain + circumstances, namely autologin to be configured and + "shutdown with password" enabled.

+
+ +
+ + CVE-2007-4569 + http://www.kde.org/info/security/advisory-20070919-1.txt + + + 2007-09-19 + 2007-09-19 + +
+ flyspray -- authentication bypass -- cgit v1.2.3