CVE-2007-1308: Null Pointer Dereference
ecma/kjshtml.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessing the content of an iframe with an ftp:// URI in the src attribute, probably due to a NULL pointer dereference.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1308?
CVE-2007-1308 is considered a medium severity vulnerability that can lead to a denial of service by crashing the application.
How do I fix CVE-2007-1308?
To mitigate CVE-2007-1308, it is recommended to upgrade to a newer version of KDE that does not have this vulnerability.
What type of attack does CVE-2007-1308 enable?
CVE-2007-1308 allows remote attackers to cause a denial of service by exploiting a NULL pointer dereference when accessing certain iframe URIs.
Which software versions are affected by CVE-2007-1308?
CVE-2007-1308 specifically affects KDE Konqueror version 3.5.5.
Is there an available patch for CVE-2007-1308?
There is no specific patch available, so upgrading to a non-affected version is the best way to address CVE-2007-1308.