PT-2012-1070 · Kde+3 · Kdelibs+5
Tim Brown
·
Published
2012-10-30
·
Updated
2012-11-12
·
CVE-2012-4513
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
KDE version 4.7.3
kdelibs versions 4.3.4
Description
The issue allows remote attackers to cause a denial of service and possibly read memory via large canvas dimensions, leading to an unexpected sign extension and a heap-based buffer over-read. Multiple vulnerabilities in the kdelibs package may lead to a violation of confidentiality and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations
For KDE version 4.7.3, consider updating to a newer version to mitigate the risk.
For kdelibs versions 4.3.4, restrict access to sensitive information and consider updating to a newer version to mitigate the risk.
As a temporary workaround, consider disabling the
scaledimageplane.h function in Konqueror until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
Buffer Overflow
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Kde
Konqueror
Red Hat
Suse
Kdelibs