|
|||||||||||
|
[BuHa-Security] DoS Vulnerability in Konqueror 3.5.7
From: <bugtraq(at)morph3us.org>
Date: Wed Aug 01 2007 - 15:20:20 EDT
| BuHa Security-Advisory #16 | Aug 01st, 2007 | | Vendor | KDE's Konqueror | | URL | http://www.konqueror.org/ | | Version | <= 3.5.7 | | Risk | Low (Denial Of Service) | --------------------------------------------------- o Description: Konqueror is the file manager for the K Desktop Environment and an Open Source web browser with HTML 4.01 compliance. Visit http://www.konqueror.org/ for detailed information. o Denial of Service:
Following HTML code forces Konqueror to crash:
Online-demo:
> (gdb) set args konqueror.html > > Program received signal SIGSEGV, Segmentation fault. > [Switching to Thread -1234381104 (LWP 5982)] > 0xb5ef84e7 in ?? () from /usr/lib/libkhtml.so. I sent a mail to KDE's security mailing list [1] and received an answer from Dirk Mueller several days later. He wrote that the HTML code triggers an assert and when commenting out the assert the backtrace ends in: > #6 0xb7bb37a4 in khtml::RenderFlow::lastLineBox (this=0x0) This issue does not seem to be exploitable. o Disclosure Timeline: 03 May 07 - DoS vulnerability discovered. 07 May 07 - Vendor contacted. 10 May 07 - Vendor confirmed vulnerability. 01 Aug 07 - Public release. o Solution: There is no solution yet. I assume the KDE developers will address this bug in an upcoming KDE release. o Credits:
Thomas Waldegger <bugtraq@morph3us.org>
If you have questions, suggestions or criticism about the advisory feel free to send me a mail. The address 'bugtraq@morph3us.org' is more a spam address than a regular mail address therefore it's possible that I ignore some mails. Please use the contact details at http://morph3us.org/ to contact me. Greets fly out to cyrus-tc, destructor, echox, Killsystem, nait, Neon, Rodnox, trappy and all members of BuHa.
Advisory online:
[1] http://www.kde.org/info/security/
-----BEGIN PGP SIGNATURE-----
iD8DBQFGsNwHkCo6/ctnOpYRA02bAJ0YjwxUB3PnYf2IKTyT0RkauZmd3QCgir16
WHuq7rPUBPx1/5nx+jJUPDg=
This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:10:40 EDT |
||||||||||
|
|||||||||||