mailing list archives
Re: Pre-advisory for Konqueror 4.7.3 (other versions may be affected)
From: Kurt Seifried <kseifried () redhat com>
Date: Thu, 11 Oct 2012 11:10:26 -0600
-----BEGIN PGP SIGNED MESSAGE-----
On 10/10/2012 07:52 PM, Kurt Seifried wrote:
On 10/10/2012 04:12 PM, Tim Brown wrote:
Taken from NDSA20121010: --8<-------- This advisory comes in 4
1) The Konqueror web browser is vulnerable to type confusion
leading to memory disclosure. The root cause of this is the
same as CVE-2010-0046 reported by Chris Rohlf which affected
Please use CVE-2012-4512 for this issue.
2) The Konqueror web browser is vulnerable to an out of bounds
memory access when accessing the canvas. In this case the
vulnerability was identified whilst playing with bug #43813 from
Google's Chrome repository.
Please use CVE-2012-4513 for this issue.
3) The Konqueror web browser is vulnerable to a NULL pointer
dereference leading to a crash.
4) The Konqueror web browser is vulnerable to a "use-after-free"
class flaw when the context menu is used whilst the document
Please use CVE-2012-4514 for this issue.
These flaws were identified during an analysis of previously
reported vulnerabilities that affected Google's Chrome web
browser. It is believed that only vulnerability 1 is/was common
to the two code bases.
Please use CVE-2012-4515 for this issue.
I'm pre-advising on these flaws since I've not heard anything
from the KDE project in about 8 months regarding 3 and 4 and we
are aware that 1 and 2 have been fixed. I'll give it 7 days and
then drop technical details. Vendors with an interest can
contact me off list.
Kurt Seifried Red Hat Security Response Team (SRT)
PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://www.enigmail.net/
-----END PGP SIGNATURE-----