CVE-2006-0019: Buffer Overflow
Published Jan 20, 2006
·Updated
Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.
Affected Software
17 affected components
KDE kde=3.3.2
KDE kde=3.2.0_beta1
KDE kde=3.3.1
KDE kde=3.2.2
KDE kde=3.2.1
KDE kde=3.4.0
KDE kde=3.4
KDE kde=3.5.0
KDE kde=3.3.x
KDE kde=3.2.0
KDE kde=3.3
KDE kde=3.2
KDE kde=3.2.3
KDE kde=3.4.2
KDE kde=3.4.1
KDE kde=3.3.0
KDE kde=3.2.x
Remediation
Patch Available
Patch Available
Event History
Jan 20, 2006
CVE Published
09:03 PM
Jan 21, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0019?
CVE-2006-0019 is considered a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2006-0019?
To fix CVE-2006-0019, upgrade to KDE version 3.5.1 or later, as this version addresses the vulnerability.
3
What versions of KDE are affected by CVE-2006-0019?
KDE versions from 3.2.0 through 3.5.0 are affected by CVE-2006-0019.
4
Can CVE-2006-0019 be exploited remotely?
Yes, CVE-2006-0019 can be exploited remotely via a crafted UTF-8 encoded URI.
5
What impact does CVE-2006-0019 have on systems?
CVE-2006-0019 can allow attackers to execute arbitrary code on affected systems.