Mailing the story:

Debian alert: New kdelibs fix cross site scripting bug

  • Mailing list (Posted by on CST)
  • Story Type: Security; Groups: Debian
A cross site scripting problem has been discovered in Konquerer, a famous browser for KDE and other programs using KHTML. The KDE team reports that Konqueror's cross site scripting protection fails to initialize the domains on sub-(i)frames correctly. As a result, Javascript is able to access any foreign subframe which is defined in the HTML source. Users of Konqueror and other KDE software that uses the KHTML rendering engine may become victim of a cookie stealing and other cross site scripting attacks.
What is your name?

What is your E-Mail address?

What is the email address of the recipient?

Add a special note from yourself?