Lucene search

K
ubuntuUbuntuUSN-822-1
HistoryAug 24, 2009 - 12:00 a.m.

KDE-Libs vulnerabilities

2009-08-2400:00:00
ubuntu.com
45

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.3 High

AI Score

Confidence

High

0.068 Low

EPSS

Percentile

93.9%

Releases

  • Ubuntu 9.04
  • Ubuntu 8.10
  • Ubuntu 8.04

Packages

  • kde4libs -
  • kdelibs -

Details

It was discovered that KDE-Libs did not properly handle certain malformed
SVG images. If a user were tricked into opening a specially crafted SVG
image, an attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program. This
issue only affected Ubuntu 9.04. (CVE-2009-0945)

It was discovered that the KDE JavaScript garbage collector did not
properly handle memory allocation failures. If a user were tricked into
viewing a malicious website, an attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2009-1687)

It was discovered that KDE-Libs did not properly handle HTML content in the
head element. If a user were tricked into viewing a malicious website, an
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-1690)

It was discovered that KDE-Libs did not properly handle the Cascading Style
Sheets (CSS) attr function call. If a user were tricked into viewing a
malicious website, an attacker could cause a denial of service or possibly
execute arbitrary code with the privileges of the user invoking the
program. (CVE-2009-1698)

OSVersionArchitecturePackageVersionFilename
Ubuntu9.04noarchkdelibs4c2a< 4:3.5.10.dfsg.1-1ubuntu8.1UNKNOWN
Ubuntu9.04noarchkdelibs< dbg-4:3.5.10.dfsg.1-1ubuntu8.1UNKNOWN
Ubuntu9.04noarchkdelibs< dev-4:3.5.10.dfsg.1-1ubuntu8.1UNKNOWN
Ubuntu9.04noarchkdelibs< c2a-4:3.5.10.dfsg.1-1ubuntu8.1UNKNOWN
Ubuntu9.04noarchkdelibs5< 4:4.2.2-0ubuntu5.1UNKNOWN
Ubuntu9.04noarchkdelibs-bin< 4:4.2.2-0ubuntu5.1UNKNOWN
Ubuntu9.04noarchkdelibs5< dbg-4:4.2.2-0ubuntu5.1UNKNOWN
Ubuntu9.04noarchkdelibs5< dev-4:4.2.2-0ubuntu5.1UNKNOWN
Ubuntu9.04noarchlibplasma-dev< 4:4.2.2-0ubuntu5.1UNKNOWN
Ubuntu9.04noarchlibplasma3< 4:4.2.2-0ubuntu5.1UNKNOWN
Rows per page:
1-10 of 211

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.3 High

AI Score

Confidence

High

0.068 Low

EPSS

Percentile

93.9%