Vulnerabilities > CVE-2002-1152 - Unspecified vulnerability in KDE 3.0/3.0.1/3.0.2

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
kde

Summary

Konqueror in KDE 3.0 through 3.0.2 does not properly detect the "secure" flag in an HTTP cookie, which could cause Konqueror to send the cookie across an unencrypted channel, which could allow remote attackers to steal the cookie via sniffing.

Vulnerable Configurations

Part Description Count
OS
Kde
3

Redhat

advisories
rhsa
idRHSA-2002:220