First published: Wed Dec 20 2006(Updated: )
The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote attackers to cause a denial of service (crash) via malformed HTML tags, possibly involving a COL SPAN tag embedded in a RANGE tag.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kde Libkhtml | <=4.2.0 | |
KDE libkhtml | <=4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6660 is classified as a denial of service vulnerability which can cause affected applications to crash.
To fix CVE-2006-6660, upgrade KDE libkhtml to version 4.2.1 or later.
CVE-2006-6660 affects KDE libkhtml versions 4.2.0 and earlier, used by applications like Konqueror and KMail.
CVE-2006-6660 can be exploited through malformed HTML tags that can lead to application crashes.
CVE-2006-6660 is generally not a risk for current systems if they have updated their KDE libkhtml beyond version 4.2.0.