PT-2012-1069 · Kde+3 · Kdelibs+4
Tim Brown
·
Published
2012-10-30
·
Updated
2023-02-13
·
CVE-2012-4512
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
kdelibs versions 4.3.4
kdelibs-devel version 4.3.4
kdelibs-debuginfo version 4.3.4
kdelibs-apidocs version 4.3.4
kdelibs-common version 4.3.4
Description
The issue concerns multiple vulnerabilities in the kdelibs package, which can lead to a disruption of confidentiality and availability of protected information. These vulnerabilities can be exploited remotely. The CSS parser in Konqueror is also affected, allowing remote attackers to cause a denial of service and possibly read memory via a crafted font face source, related to type confusion.
Recommendations
For kdelibs version 4.3.4, consider updating to a newer version to mitigate the risk.
For kdelibs-devel version 4.3.4, consider updating to a newer version to mitigate the risk.
For kdelibs-debuginfo version 4.3.4, consider updating to a newer version to mitigate the risk.
For kdelibs-apidocs version 4.3.4, consider updating to a newer version to mitigate the risk.
For kdelibs-common version 4.3.4, consider updating to a newer version to mitigate the risk.
As a temporary workaround, consider restricting access to the CSS parser in Konqueror to minimize the risk of exploitation.
Exploit
Fix
DoS
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Konqueror
Red Hat
Suse
Kdelibs