Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 438452 (CVE-2012-4512) - <kde-base/konqueror-4.9.3-r1: Multiple vulnerabilities (CVE-2012-{4512,4513,4514,4515})
Summary: <kde-base/konqueror-4.9.3-r1: Multiple vulnerabilities (CVE-2012-{4512,4513,4...
Status: RESOLVED FIXED
Alias: CVE-2012-4512
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL:
Whiteboard: B2 [glsa]
Keywords:
Depends on: kde-4.9.3-stable
Blocks:
  Show dependency tree
 
Reported: 2012-10-15 08:54 UTC by Agostino Sarubbo
Modified: 2014-06-27 14:31 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-10-15 08:54:33 UTC
From oss-security:

1) The Konqueror web browser is vulnerable to type confusion 
leading to memory disclosure.  The root cause of this is the same
as CVE-2010-0046 reported by Chris Rohlf which affected WebKit.

2) The Konqueror web browser is vulnerable to an out of bounds 
memory access when accessing the canvas.  In this case the 
vulnerability was identified whilst playing with bug #43813 from 
Google's Chrome repository.

3) The Konqueror web browser is vulnerable to a NULL pointer 
dereference leading to a crash.

4) The Konqueror web browser is vulnerable to a "use-after-free" 
class flaw when the context menu is used whilst the document DOM
that is being changed from within Javascript.

1 and 2 are already fixed.
3 and 4 are not fixed.
Comment 1 Michael Palimaka (kensington) gentoo-dev 2012-10-23 14:28:07 UTC
Are there upstream bug numbers for each of these issues?
Comment 2 Michael Palimaka (kensington) gentoo-dev 2012-11-09 14:22:12 UTC
After talking with ago, we were able to confirm that all these CVEs are fixed by 4.9.3
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2012-11-11 16:22:05 UTC
CVE-2012-4515 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4515):
  Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in
  Konqueror in KDE 4.7.3, when the context menu is shown, allows remote
  attackers to cause a denial of service (crash) and possibly execute
  arbitrary code by accessing an iframe when it is being updated.

CVE-2012-4514 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4514):
  rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote
  attackers to cause a denial of service (NULL pointer dereference) via a
  crafted web page, related to "trying to reuse a frame with a null part."

CVE-2012-4513 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4513):
  khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote
  attackers to cause a denial of service (crash) and possibly read memory via
  large canvas dimensions, which leads to an unexpected sign extension and a
  heap-based buffer over-read.
Comment 4 Agostino Sarubbo gentoo-dev 2012-11-30 18:51:10 UTC
The stabilization has been done, please file the glsa request
Comment 5 Sean Amoss (RETIRED) gentoo-dev Security 2012-12-01 14:03:19 UTC
Filing a new GLSA request.
Comment 6 Andreas K. Hüttel archtester gentoo-dev 2013-03-06 12:02:59 UTC
Nothing to do for the maintainers here anymore. Yawn. Does anyone still read this?
Comment 7 GLSAMaker/CVETool Bot gentoo-dev 2014-06-27 14:31:57 UTC
This issue was resolved and addressed in
 GLSA 201406-31 at http://security.gentoo.org/glsa/glsa-201406-31.xml
by GLSA coordinator Sergey Popov (pinkbyte).