REDHAT-BUG-513813: Buffer Overflow
Common Vulnerabilities and Exposures assigned an identifier of CVE-2009-1725 to the following vulnerability:
KDE Konqueror allows remote attackers to cause a denial of service and potentially execute arbitrary code via a buffer overflow due to improper handling of numeric character references. This issue was first discovered in WebKit and fixed in KHTML (trunk, 4.3 branch and 3.5 branch) a few hours ago: http://websvn.kde.org/?view=rev&revision=1002162 http://websvn.kde.org/?view=rev&revision=1002163 http://websvn.kde.org/?view=rev&revision=1002164
I am already working on Fedora updates.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-513813?
The severity of REDHAT-BUG-513813 is classified as a denial of service vulnerability which may also allow arbitrary code execution.
How do I fix REDHAT-BUG-513813?
To fix REDHAT-BUG-513813, update KDE Konqueror or KHTML to versions beyond the vulnerable range specified.
What products are affected by REDHAT-BUG-513813?
REDHAT-BUG-513813 affects KDE Konqueror versions 3.5 through trunk and KHTML versions 3.5 through trunk.
What kind of attack can occur due to REDHAT-BUG-513813?
Attacks exploiting REDHAT-BUG-513813 can result in denial of service and potential arbitrary code execution.
Is REDHAT-BUG-513813 related to any known CVE?
Yes, REDHAT-BUG-513813 is linked to the Common Vulnerabilities and Exposures identifier CVE-2009-1725.