PT-2008-6764 · Kde · Kde Konqueror

Jeremy Brown

·

Published

2008-12-24

·

Updated

2017-09-29

·

CVE-2008-5712

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions KDE Konqueror version 3.5.9
Description The issue affects the HTML parser, allowing remote attackers to cause a denial of service, resulting in an application crash. This can be achieved through a long COLOR attribute in an HR element, or a long BGCOLOR or BORDERCOLOR attribute in TABLE, TD, or TR elements.
Recommendations For KDE Konqueror version 3.5.9, consider disabling the HTML parser temporarily as a workaround until a patch is available. Restrict access to potentially malicious HTML content to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5712

Affected Products

Kde Konqueror