Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-4513

Опубликовано: 30 окт. 2012
Источник: redhat
CVSS2: 5.8
EPSS Средний

Описание

khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer over-read.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kdelibsNot affected
Red Hat Enterprise Linux 6kdelibsFixedRHSA-2012:141630.10.2012
Red Hat Enterprise Linux Desktop (v. 6)FixedRHSA-2012:141830.10.2012
Red Hat Enterprise Linux HPC Node (v. 6)FixedRHSA-2012:141830.10.2012
Red Hat Enterprise Linux Server (v. 6)FixedRHSA-2012:141830.10.2012
Red Hat Enterprise Linux Workstation (v. 6)FixedRHSA-2012:141830.10.2012

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=865741kdelibs: Heap-based buffer over-read when calculating dimensions of the canvas within the scale loop

EPSS

Процентиль: 96%
0.22677
Средний

5.8 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer over-read.

nvd
почти 13 лет назад

khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer over-read.

debian
почти 13 лет назад

khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remot ...

github
больше 3 лет назад

khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer over-read.

oracle-oval
больше 12 лет назад

ELSA-2012-1418: kdelibs security update (CRITICAL)

EPSS

Процентиль: 96%
0.22677
Средний

5.8 Medium

CVSS2