Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 173303

Summary: kde-base/kdelibs UTF8 issue in KJS? (CVE-2007-0242 )
Product: Gentoo Security Reporter: Sune Kloppenborg Jeppesen (RETIRED) <jaervosz>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED DUPLICATE    
Severity: normal CC: kde
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0125.html
Whiteboard:
Package list:
Runtime testing required: ---

Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-04-04 06:33:34 UTC
Mandriva Linux Security Advisory MDKSA-2007:076 
  http://www.mandriva.com/security/ 
  _______________________________________________________________________ 
   
  Package : kdelibs 
  Date : April 3, 2007 
  Affected: 2007.0, Corporate 3.0, Corporate 4.0 
  _______________________________________________________________________ 
   
  Problem Description: 
   
  A bug was discovered in KJS where UTF8 decoding did not reject 
  overlong sequences. This vulnerability is similar to that discovered 
  by Andreas Nolden in QT3 and QT4, but at this current time there is 
  no known exploit for this issue. 
   
  Updated packages have been patched to address this issue. 
  _______________________________________________________________________ 
 
 References: 
   
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0242
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-04-04 06:34:00 UTC
KDE please advise.
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-04-04 06:41:33 UTC
Woops we already have a bug for this one.

*** This bug has been marked as a duplicate of bug 172746 ***