Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://www.kde.org/info/security/advisory-20040823-1.txt http://www.osvdb.org/9117
http://secunia.com/advisories/12341
http://www.acros.si/papers/session_fixation.pdf
http://www.vuxml.org/freebsd/2797b27a-f55b-11d8-81b0-000347a4fa7d.html
Insight
The following package is affected: kdelibs
CVE-2004-0746
Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
Severity
Classification
-
CVE CVE-2004-0746 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities