CVE-2007-3143

Publication date 11 June 2007

Last updated 24 July 2024


Ubuntu priority

Visual truncation vulnerability in Konqueror 3.5.5 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after a certain number of characters, as demonstrated by a phishing attack using HTTP Basic Authentication.

Read the notes from the security team

Status

Package Ubuntu Release Status
kdebase 7.10 gutsy
Not affected
7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected
opera 7.10 gutsy
Fixed 9.25-20071214.6gutsy1
7.04 feisty
Fixed 9.23-20070809.6feisty1
6.10 edgy
Fixed 9.23-20070809.6edgy1
6.06 LTS dapper
Fixed 9.23-20070809.6dapper1

Notes


jdstrand

CVE references konqueror 3.5.5, but securityfocus references opera. securityfocus says that other browsers may be affected, and there is test exploit code. Need to verify on konqueror.


kees

this may already be solved from CVE-2007-3820, CVE-2007-4224, and CVE-2007-4225.