Bug 94164 - recent java/javascript sandbox bypassing issue seems still to work with fixed java versions
Summary: recent java/javascript sandbox bypassing issue seems still to work with fixed...
Status: RESOLVED FIXED
Alias: None
Product: konqueror
Classification: Applications
Component: kjava (show other bugs)
Version: unspecified
Platform: Gentoo Packages Linux
: NOR critical
Target Milestone: ---
Assignee: Konqueror Developers
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2004-11-30 13:42 UTC by Carsten Lohrke
Modified: 2005-01-04 11:51 UTC (History)
0 users

See Also:
Latest Commit:
Version Fixed In:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carsten Lohrke 2004-11-30 13:42:38 UTC
Version:            (using KDE KDE 3.3.1)
Installed from:    Gentoo Packages

The following browser tests 

http://www.heise.de/security/dienste/browsercheck/tests/java.shtml
http://bcheck.scanit.be/bcheck/

let assume, that konqeuror is vulnerable, even though fixed java versions are in use (sun-jdk 1.4.2_06, blackdown-jdk-1.4.2_01)


for reference:
http://bugs.gentoo.org/show_bug.cgi?id=72750
Comment 1 Stephan Kulow 2004-12-09 10:22:43 UTC
this went into 3.3.2
Comment 2 Carsten Lohrke 2004-12-09 19:02:43 UTC
I did not investigate further. Is this similar to Opera's recent Java sandbox problem, or a minor issue? Does it need to be backported for KDE 3.2.3?
Comment 3 Carsten Lohrke 2004-12-10 20:53:17 UTC
Reopening for two reasons:

- A bit more information about the issue would be fine.

- Trying the java (#1) test from http://bcheck.scanit.be/bcheck/, konqueror 3.3.2 pops up a window, asking if I want to let javascript to open a new window, but then closes it again after a second. Either ask or not, but don't "withdraw" an opened dialog window.
Comment 4 Carsten Lohrke 2004-12-11 16:37:40 UTC
It's even worse: Executing the second test from http://secunia.com/advisories/11978/ (Bug 84352: Browser Frame Injection Vulnerability) opens the above named dialog ~20 times (infinite, but hit some constraint/max constant?), forcing me to kill konqueror and all the kio_http connections.
Comment 5 Waldo Bastian 2005-01-04 11:51:45 UTC
Fixed see: http://www.kde.org/info/security/advisory-20041220-1.txt for more information

Please open a new bugreport if you encounter problems with popup dialogs.