PT-2007-2723 · Kde+1 · Kde Konqueror+1

Published

2007-03-07

·

Updated

2018-10-16

·

CVE-2007-1308

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions KDE Konqueror version 3.5.5
Description The issue allows remote attackers to cause a denial of service, resulting in a crash, by accessing the content of an iframe with an ftp:// URI in the src attribute, likely due to a NULL pointer dereference.
Recommendations For KDE Konqueror version 3.5.5, consider avoiding the use of iframes with ftp:// URIs in the src attribute until a fix is available. As a temporary workaround, restrict access to iframes with external sources to minimize the risk of exploitation.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-1308
RHSA-2007:0909
RHSA-2007_0909

Affected Products

Kde Konqueror
Red Hat