Back

HIGH

security flaw

Published May 20, 2004

Description

The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 20, 2004
Updated Aug 8, 2024
Reserved Apr 16, 2004
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date May 17, 2004