CVE-2009-1725: Buffer Overflow
Common Vulnerabilities and Exposures assigned an identifier of CVE-2009-1725 to the following vulnerability:
KDE Konqueror allows remote attackers to cause a denial of service and potentially execute arbitrary code via a buffer overflow due to improper handling of numeric character references. This issue was first discovered in WebKit and fixed in KHTML (trunk, 4.3 branch and 3.5 branch) a few hours ago: http://websvn.kde.org/?view=rev&revision=1002162 http://websvn.kde.org/?view=rev&revision=1002163 http://websvn.kde.org/?view=rev&revision=1002164
I am already working on Fedora updates.
Other sources
WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What types of attacks are possible with CVE-2009-1725?
CVE-2009-1725 allows remote attackers to cause a denial of service and potentially execute arbitrary code via a buffer overflow in KDE Konqueror.
Which software versions are affected by CVE-2009-1725?
CVE-2009-1725 affects multiple versions of Apple Safari and Apple iPhone OS including versions up to 4.0.
What is the severity level of CVE-2009-1725?
CVE-2009-1725 has been classified with a moderate to high severity due to its potential to cause denial of service and execute arbitrary code.
How can organizations mitigate the risks associated with CVE-2009-1725?
Organizations can mitigate risks from CVE-2009-1725 by applying the latest security updates and patches for the affected software.
Is there an official patch for CVE-2009-1725?
Yes, Apple has released official patches addressing the vulnerabilities associated with CVE-2009-1725 in affected versions of Safari and iPhone OS.