Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 241112 (CVE-2008-4514) - kde-base/konqueror-3.5.9 HTML parser DOS (CVE-2008-{4514,5712})
Summary: kde-base/konqueror-3.5.9 HTML parser DOS (CVE-2008-{4514,5712})
Status: RESOLVED OBSOLETE
Alias: CVE-2008-4514
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Low minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A4 [upstream]
Keywords:
Depends on: 271889
Blocks:
  Show dependency tree
 
Reported: 2008-10-10 13:28 UTC by Stefan Behte (RETIRED)
Modified: 2013-09-03 02:53 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2008-10-10 13:28:56 UTC
CVE-2008-4514 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4514):
  The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to
  cause a denial of service (application crash) via a font tag with a
  long color value, which triggers an assertion error.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2008-11-05 23:35:48 UTC
http://www.milw0rm.com/exploits/6689

perl -e 'print "<html>\n" . "<font color=" . "A" x 500000 . "\n</html>"' > kdie.html 
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2008-12-27 18:58:26 UTC
CVE-2008-5712 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5712):
  The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to
  cause a denial of service (application crash) via (1) a long COLOR
  attribute in an HR element; or a long (a) BGCOLOR or (b) BORDERCOLOR
  attribute in a (2) TABLE, (3) TD, or (4) TR element.  NOTE: the FONT
  vector is already covered by CVE-2008-4514.

Comment 3 Theo Chatzimichos (RETIRED) archtester gentoo-dev Security 2009-05-27 21:42:21 UTC
bugs 241112 239565 252686 are security bugs for konqueror-3.5
I plan to stabilize kde-3.5.10 really soon. We can't do anything for those bugs, because upstream development for kde3 has stopped (so even reporting those we won't have feedback) and of course we can't mask the default kde3 browser. I can search for possible patches in other distros, although i highly doubt i'll find any since most distros stopped supporting kde3. Thanks
Comment 4 Theo Chatzimichos (RETIRED) archtester gentoo-dev Security 2009-05-30 17:19:25 UTC
i have opened stabilization bug for kde 3.5.10, adding it in depend buglist
Comment 5 Samuli Suominen (RETIRED) gentoo-dev 2009-11-07 20:06:08 UTC
=konqueror-3* is now masked for removal
Comment 6 Theo Chatzimichos (RETIRED) archtester gentoo-dev Security 2010-01-23 15:30:48 UTC
KDE 3 is not in tree any more. CC us again if you need anything. thanks
Comment 7 Chris Reffett (RETIRED) gentoo-dev Security 2013-09-03 02:53:43 UTC
KDE 3.5 is long gone.