PT-2008-6764 · Kde · Kde Konqueror
Jeremy Brown
·
Published
2008-12-24
·
Updated
2017-09-29
·
CVE-2008-5712
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
KDE Konqueror version 3.5.9
Description
The issue affects the HTML parser, allowing remote attackers to cause a denial of service, resulting in an application crash. This can be achieved through a long COLOR attribute in an HR element, or a long BGCOLOR or BORDERCOLOR attribute in TABLE, TD, or TR elements.
Recommendations
For KDE Konqueror version 3.5.9, consider disabling the HTML parser temporarily as a workaround until a patch is available. Restrict access to potentially malicious HTML content to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kde Konqueror