Описание
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
A heap-based buffer overflow flaw was found in the way the CSS parser of the Document Object Model's (DOM) implementation of KDE libraries performed processing of a location of a particular font face source. A remote attacker with privileges could provide a specially-crafted web page that, when opened in an application linked against KDE libraries, would lead to the application crashing or potential execution of arbitrary code.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | kdelibs | Not affected | ||
Red Hat Enterprise Linux 6 | kdelibs | Fixed | RHSA-2012:1416 | 30.10.2012 |
Red Hat Enterprise Linux Desktop (v. 6) | Fixed | RHSA-2012:1418 | 30.10.2012 | |
Red Hat Enterprise Linux HPC Node (v. 6) | Fixed | RHSA-2012:1418 | 30.10.2012 | |
Red Hat Enterprise Linux Server (v. 6) | Fixed | RHSA-2012:1418 | 30.10.2012 | |
Red Hat Enterprise Linux Workstation (v. 6) | Fixed | RHSA-2012:1418 | 30.10.2012 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.8 Medium
CVSS2
Связанные уязвимости
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 all ...
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
EPSS
6.8 Medium
CVSS2