MEDIUM · 5.0

CVE-2004-1145

Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java ...

Vulnerability Description

Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
Ethereal GroupEthereal0.9
SgiPropack3.0
ConectivaLinux9.0
AltlinuxAlt Linux2.3
DebianDebian Linux3.0
RedhatEnterprise Linux2.1
RedhatEnterprise Linux Desktop3.0
RedhatLinux Advanced Workstation2.1
SuseSuse Linux8.0

References

FAQ

What is CVE-2004-1145?

CVE-2004-1145 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java ...

How severe is CVE-2004-1145?

CVE-2004-1145 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-1145?

Check the references section above for vendor advisories and patch information. Affected products include: Ethereal Group Ethereal, Sgi Propack, Conectiva Linux, Altlinux Alt Linux, Debian Debian Linux.