CVE-2008-5712: Input Validation
Published Dec 24, 2008
·Updated
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COLOR attribute in an HR element; or a long (a) BGCOLOR or (b) BORDERCOLOR attribute in a (2) TABLE, (3) TD, or (4) TR element. NOTE: the FONT vector is already covered by CVE-2008-4514.
Affected Software
1 affected component
Konqueror=3.5.9
Event History
Dec 24, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·06:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-5712?
CVE-2008-5712 is classified as a denial of service vulnerability.
2
How do I fix CVE-2008-5712?
To fix CVE-2008-5712, upgrade to a version of KDE Konqueror that is not affected.
3
What software is affected by CVE-2008-5712?
KDE Konqueror version 3.5.9 is the affected software for CVE-2008-5712.
4
What types of attacks can be executed using CVE-2008-5712?
CVE-2008-5712 allows attackers to cause application crashes through specially crafted HTML attributes.
5
Is CVE-2008-5712 specific to certain HTML elements?
Yes, CVE-2008-5712 specifically affects the HR, TABLE, TD, and TR HTML elements.