First published: Sun Jul 26 2009(Updated: )
Common Vulnerabilities and Exposures assigned an identifier of <a href="https://access.redhat.com/security/cve/CVE-2009-1725">CVE-2009-1725</a> to the following vulnerability: KDE Konqueror allows remote attackers to cause a denial of service and potentially execute arbitrary code via a buffer overflow due to improper handling of numeric character references. This issue was first discovered in WebKit and fixed in KHTML (trunk, 4.3 branch and 3.5 branch) a few hours ago: <a href="http://websvn.kde.org/?view=rev&revision=1002162">http://websvn.kde.org/?view=rev&revision=1002162</a> <a href="http://websvn.kde.org/?view=rev&revision=1002163">http://websvn.kde.org/?view=rev&revision=1002163</a> <a href="http://websvn.kde.org/?view=rev&revision=1002164">http://websvn.kde.org/?view=rev&revision=1002164</a> I am already working on Fedora updates.
Affected Software | Affected Version | How to fix |
---|---|---|
Konqueror | >=3.5<=trunk>=4.3<=trunk | |
KDE KHTML | >=3.5<=trunk>=4.3<=trunk |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-513813 is classified as a denial of service vulnerability which may also allow arbitrary code execution.
To fix REDHAT-BUG-513813, update KDE Konqueror or KHTML to versions beyond the vulnerable range specified.
REDHAT-BUG-513813 affects KDE Konqueror versions 3.5 through trunk and KHTML versions 3.5 through trunk.
Attacks exploiting REDHAT-BUG-513813 can result in denial of service and potential arbitrary code execution.
Yes, REDHAT-BUG-513813 is linked to the Common Vulnerabilities and Exposures identifier CVE-2009-1725.