Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.52398
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: kdelibs
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to the system
as announced in the referenced advisory.

The following packages are affected:
kdelibs
kdebase
linux-opera
opera
firefox
linux-mozilla
linux-mozilla-devel
mozilla-gtk1
mozilla
netscape7

CVE-2004-0717
Opera 7.51 for Windows and 7.50 for Linux does not properly prevent a
frame in one domain from injecting content into a frame that belongs
to another domain, which facilitates web site spoofing and other
attacks, aka the frame injection vulnerability.

CVE-2004-0718
The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4)
Netscape 7.1 web browsers do not properly prevent a frame in one
domain from injecting content into a frame that belongs to another
domain, which facilitates web site spoofing and other attacks, aka the
frame injection vulnerability.

CVE-2004-0721
Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly
prevent a frame in one domain from injecting content into a frame that
belongs to another domain, which facilitates web site spoofing and
other attacks, aka the frame injection vulnerability.

Solution:
Update your system with the appropriate patches or
software upgrades.

http://secunia.com/advisories/11978/
http://bugzilla.mozilla.org/show_bug.cgi?id=246448
ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdelibs-htmlframes.patch
ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdebase-htmlframes.patch
http://www.vuxml.org/freebsd/641859e8-eca1-11d8-b913-000c41e2cdad.html

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2004-0717
http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/
http://secunia.com/advisories/11978
XForce ISS Database: http-frame-spoof(1598)
https://exchange.xforce.ibmcloud.com/vulnerabilities/1598
Common Vulnerability Exposure (CVE) ID: CVE-2004-0718
BugTraq ID: 15495
http://www.securityfocus.com/bid/15495
Debian Security Information: DSA-777 (Google Search)
http://www.debian.org/security/2005/dsa-777
Debian Security Information: DSA-810 (Google Search)
http://www.debian.org/security/2005/dsa-810
http://marc.info/?l=bugtraq&m=109900315219363&w=2
http://www.mandriva.com/security/advisories?name=MDKSA-2004:082
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4756
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9997
http://www.redhat.com/support/errata/RHSA-2004-421.html
SCO Security Bulletin: SCOSA-2005.49
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
SuSE Security Announcement: SUSE-SA:2004:036 (Google Search)
http://www.novell.com/linux/security/advisories/2004_36_mozilla.html
Common Vulnerability Exposure (CVE) ID: CVE-2004-0721
Bugtraq: 20040811 KDE Security Advisories: Temporary File and Konqueror Frame Injection Vulnerabilities (Google Search)
http://marc.info/?l=bugtraq&m=109225538901170&w=2
Conectiva Linux advisory: CLA-2004:864
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000864
http://security.gentoo.org/glsa/glsa-200408-13.xml
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11371
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.