Secunia Research: Konqueror Download Dialog Source Spoofing

======================================================================

                     Secunia Research 17/03/2005

           - Konqueror Download Dialog Source Spoofing -

======================================================================
Table of Contents

Affected Software....................................................1
Severity.............................................................2
Description of Vulnerability.........................................3
Solution.............................................................4
Time Table...........................................................5
Credits..............................................................6
About Secunia........................................................7
Verification.........................................................8

======================================================================
1) Affected Software

Konqueror 3.x

Other versions may also be affected.

======================================================================
2) Severity

Rating: Less critical
Impact: Spoofing
Where:  From remote

======================================================================
3) Description of Vulnerability

Secunia Research has discovered a vulnerability in Konqueror, which
can be exploited by malicious people to spoof the source displayed in
the Download Dialog box.

The problem is that long sub-domains and paths aren't displayed
correctly, which therefore can be exploited to obfuscate what is
being displayed in the source field and title bar of the Download
Dialog box.

The vulnerability has been confirmed in Konqueror version 3.2.2 and
3.3.1. Other versions may also be affected.

KDE bug report:
http://bugs.kde.org/show_bug.cgi?id=96297

======================================================================
4) Solution

Currently, no solution is available.

Do not follow download links from untrusted sources.

======================================================================
5) Time Table

04/01/2005 - Vulnerability reported to vendor and initial reply
             recieved from vendor.
17/03/2005 - Public disclosure.

======================================================================
6) Credits

Discovered by Jakob Balle, Secunia Research.

======================================================================
7) About Secunia

Secunia collects, validates, assesses, and writes advisories regarding
all the latest software vulnerabilities disclosed to the public. These
advisories are gathered in a publicly available database at the
Secunia web site:

http://secunia.com/

Secunia offers services to our customers enabling them to receive all
relevant vulnerability information to their specific system
configuration.

Secunia offers a FREE mailing list called Secunia Security Advisories:

http://secunia.com/secunia_security_advisories/

======================================================================
8) Verification

Please verify this advisory by visiting the Secunia web site:
http://secunia.com/secunia_research/2005-1/advisory/

Complete list of vulnerability reports released by Secunia Research:
http://secunia.com/secunia_research/

======================================================================