Summary: | <kde-base/konqueror-4.9.3-r1: Multiple vulnerabilities (CVE-2012-{4512,4513,4514,4515}) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | ||
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B2 [glsa] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 442394 | ||
Bug Blocks: |
Description
Agostino Sarubbo
2012-10-15 08:54:33 UTC
Are there upstream bug numbers for each of these issues? After talking with ago, we were able to confirm that all these CVEs are fixed by 4.9.3 CVE-2012-4515 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4515): Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by accessing an iframe when it is being updated. CVE-2012-4514 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4514): rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted web page, related to "trying to reuse a frame with a null part." CVE-2012-4513 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4513): khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer over-read. The stabilization has been done, please file the glsa request Filing a new GLSA request. Nothing to do for the maintainers here anymore. Yawn. Does anyone still read this? This issue was resolved and addressed in GLSA 201406-31 at http://security.gentoo.org/glsa/glsa-201406-31.xml by GLSA coordinator Sergey Popov (pinkbyte). |