Lucene search

K
freebsdFreeBSD890B6B22-70FA-11E4-91AE-5453ED2E2B49
HistoryNov 13, 2014 - 12:00 a.m.

kwebkitpart, kde-runtime -- insufficient input validation

2014-11-1300:00:00
vuxml.freebsd.org
15

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.003

Percentile

70.4%

Albert Aastals Cid reports:

kwebkitpart and the bookmarks:// io slave were not sanitizing
input correctly allowing to some javascript being executed on the
context of the referenced hostname.
Whilst in most cases, the JavaScript will be executed in an
untrusted context, with the bookmarks IO slave, it will be executed
in the context of the referenced hostname. It should however be
noted that KDE mitigates this risk by attempting to ensure that
such URLs cannot be embedded directly into Internet hosted
content.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchkde-runtime< 4.14.2_2UNKNOWN
FreeBSDanynoarchkwebkitpart< 1.3.2_4UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.003

Percentile

70.4%