Lucene search

K
freebsdFreeBSDD8FBF13A-6215-11DB-A59E-0211D85F11FB
HistoryOct 14, 2006 - 12:00 a.m.

kdelibs -- integer overflow in khtml

2006-10-1400:00:00
vuxml.freebsd.org
22

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.115

Percentile

95.3%

Red Hat reports:

An integer overflow flaw was found in the way Qt handled pixmap
images. The KDE khtml library uses Qt in such a way that untrusted
parameters could be passed to Qt, triggering the overflow.
An attacker could for example create a malicious web page that when
viewed by a victim in the Konqueror browser would cause Konqueror
to crash or possibly execute arbitrary code with the privileges of
the victim.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchkdelibs< 3.5.4_4UNKNOWN
FreeBSDanynoarchkdelibs-nocups< 3.5.4_4UNKNOWN
FreeBSDanynoarchqt< 3.3.6_3UNKNOWN
FreeBSDanynoarchqt-copy< 3.3.6_3UNKNOWN

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.115

Percentile

95.3%