Description
The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T00:17:14.648Z
Reserved: 2004-04-16T00:00:00.000Z
Link: CVE-2004-0411
No data.
Status : Modified
Published: 2004-07-07T04:00:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2004-0411
OpenCVE Enrichment
No data.
Weaknesses