PT-2012-1069 · Kde+3 · Kdelibs+4

·

CVE-2012-4512

·

Published

2012-10-30

·

Updated

2023-02-13

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions kdelibs versions 4.3.4 kdelibs-devel version 4.3.4 kdelibs-debuginfo version 4.3.4 kdelibs-apidocs version 4.3.4 kdelibs-common version 4.3.4
Description The issue concerns multiple vulnerabilities in the kdelibs package, which can lead to a disruption of confidentiality and availability of protected information. These vulnerabilities can be exploited remotely. The CSS parser in Konqueror is also affected, allowing remote attackers to cause a denial of service and possibly read memory via a crafted font face source, related to type confusion.
Recommendations For kdelibs version 4.3.4, consider updating to a newer version to mitigate the risk. For kdelibs-devel version 4.3.4, consider updating to a newer version to mitigate the risk. For kdelibs-debuginfo version 4.3.4, consider updating to a newer version to mitigate the risk. For kdelibs-apidocs version 4.3.4, consider updating to a newer version to mitigate the risk. For kdelibs-common version 4.3.4, consider updating to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to the CSS parser in Konqueror to minimize the risk of exploitation.

Exploit

Fix

DoS

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06140
BDU:2015-06141
BDU:2015-06142
BDU:2015-06143
BDU:2015-06144
BDU:2015-08894
BDU:2015-08895
BDU:2015-08896
BDU:2015-08897
BDU:2015-08898
CESA-2012_1416
CESA-2012_1418
CVE-2012-4512
RHSA-2012:1416
RHSA-2012_1416
SUSE-SU-2013_1559-1

Affected Products

Centos
Konqueror
Red Hat
Suse
Kdelibs