Skip to main content

KDE KHTML Numeric Character References Memory Corruption Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 28 Jul 2009 5334 Views

RISK: Medium Risk

A vulnerability has been identified in KDE, which could be exploited by malicious people to potentially compromise a user's system.

The vulnerability is caused due to an error in KHTML when processing numeric character references and can be exploited to corrupt memory.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • KDE 3.x
  • KDE 4.x

Solutions

There is no patch available for this vulnerability currently.

Fixed in the SVN repository:

  • http://websvn.kde.org/?view=rev&revision=1002162
  • http://websvn.kde.org/?view=rev&revision=1002163
  • http://websvn.kde.org/?view=rev&revision=1002164

  • Vulnerability Identifier

    • No CVE information is available

    Source