First published: Mon Dec 22 2008(Updated: )
HTMLTokenizer::scriptHandler in Konqueror in KDE 3.5.9 and 3.5.10 allows remote attackers to cause a denial of service (application crash) via an invalid document.load call that triggers use of a deleted object. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KDE Kde Beta 3 | =3.5.9 | |
KDE Kde Beta 3 | =3.5.10 | |
Konqueror |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5698 has been classified as a denial of service vulnerability affecting Konqueror.
CVE-2008-5698 can cause Konqueror to crash due to an invalid document.load call that leads to the use of a deleted object.
Versions of Konqueror prior to the KDE 3.5.10 release are affected by CVE-2008-5698.
The best mitigation for CVE-2008-5698 is to upgrade to a patched version of Konqueror or KDE, specifically 3.5.10 or later.
If CVE-2008-5698 is detected on your system, you should update to a secure version of the software as soon as possible.