Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 438452 (CVE-2012-4512)

Summary: <kde-base/konqueror-4.9.3-r1: Multiple vulnerabilities (CVE-2012-{4512,4513,4514,4515})
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B2 [glsa]
Package list:
Runtime testing required: ---
Bug Depends on: 442394    
Bug Blocks:    

Description Agostino Sarubbo gentoo-dev 2012-10-15 08:54:33 UTC
From oss-security:

1) The Konqueror web browser is vulnerable to type confusion 
leading to memory disclosure.  The root cause of this is the same
as CVE-2010-0046 reported by Chris Rohlf which affected WebKit.

2) The Konqueror web browser is vulnerable to an out of bounds 
memory access when accessing the canvas.  In this case the 
vulnerability was identified whilst playing with bug #43813 from 
Google's Chrome repository.

3) The Konqueror web browser is vulnerable to a NULL pointer 
dereference leading to a crash.

4) The Konqueror web browser is vulnerable to a "use-after-free" 
class flaw when the context menu is used whilst the document DOM
that is being changed from within Javascript.

1 and 2 are already fixed.
3 and 4 are not fixed.
Comment 1 Michael Palimaka (kensington) gentoo-dev 2012-10-23 14:28:07 UTC
Are there upstream bug numbers for each of these issues?
Comment 2 Michael Palimaka (kensington) gentoo-dev 2012-11-09 14:22:12 UTC
After talking with ago, we were able to confirm that all these CVEs are fixed by 4.9.3
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2012-11-11 16:22:05 UTC
CVE-2012-4515 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4515):
  Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in
  Konqueror in KDE 4.7.3, when the context menu is shown, allows remote
  attackers to cause a denial of service (crash) and possibly execute
  arbitrary code by accessing an iframe when it is being updated.

CVE-2012-4514 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4514):
  rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote
  attackers to cause a denial of service (NULL pointer dereference) via a
  crafted web page, related to "trying to reuse a frame with a null part."

CVE-2012-4513 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4513):
  khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote
  attackers to cause a denial of service (crash) and possibly read memory via
  large canvas dimensions, which leads to an unexpected sign extension and a
  heap-based buffer over-read.
Comment 4 Agostino Sarubbo gentoo-dev 2012-11-30 18:51:10 UTC
The stabilization has been done, please file the glsa request
Comment 5 Sean Amoss (RETIRED) gentoo-dev Security 2012-12-01 14:03:19 UTC
Filing a new GLSA request.
Comment 6 Andreas K. Hüttel archtester gentoo-dev 2013-03-06 12:02:59 UTC
Nothing to do for the maintainers here anymore. Yawn. Does anyone still read this?
Comment 7 GLSAMaker/CVETool Bot gentoo-dev 2014-06-27 14:31:57 UTC
This issue was resolved and addressed in
 GLSA 201406-31 at http://security.gentoo.org/glsa/glsa-201406-31.xml
by GLSA coordinator Sergey Popov (pinkbyte).