CVE-2002-1152
https://notcve.org/view.php?id=CVE-2002-1152
Konqueror in KDE 3.0 through 3.0.2 does not properly detect the "secure" flag in an HTTP cookie, which could cause Konqueror to send the cookie across an unencrypted channel, which could allow remote attackers to steal the cookie via sniffing. Konqueror en KDE 3.0 a 3.0.2 no detecta adecuadamente la señal (flag) en una cookieHTTP, lo que podría causar que Konqueror mandase la cookie por un canal no cifrado, que podría ser vista por atacantes espiando (sniffing) la conexión. • http://marc.info/?l=bugtraq&m=103175827225044&w=2 http://www.iss.net/security_center/static/10083.php http://www.kde.org/info/security/advisory-20020908-1.txt http://www.redhat.com/support/errata/RHSA-2002-220.html http://www.securityfocus.com/bid/5691 •
CVE-2002-0970
https://notcve.org/view.php?id=CVE-2002-0970
The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack. La capacidad SSL en Konqueror 3.0.2 y anteriores no verifica las restriccíones básicas de una certificad intermedio firmado por una AC (Autoridad Certificadora), lo que permite a atacantes remotos falsear los certificados de sitios de confianza mediante un ataque de hombre en el medio (man-in-the-middle. • ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-047.0.txt http://archives.neohapsis.com/archives/bugtraq/2002-08/0170.html http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000519 http://marc.info/?l=bugtraq&m=102918241005893&w=2 http://www.debian.org/security/2002/dsa-155 http://www.kde.org/info/security/advisory-20020818-1.txt http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:058 http://www.redhat.com/support/errata/RHSA-2002-220.html http •