-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------ Arch Linux Security Warning ALSW 2007-#13 - ------------------------------------------------------------
Name: kdebase Date: 2007-03-08 Severity: Normal Warning #: 2007-#13 - ------------------------------------------------------------ Product Background =================== KDE ( K Desktop Environment) Base programs. Problem Background =================== Konqueror crashes if JavaScript code tries to read the source of a child iframe which is set to an FTP URL. Impact ====== It is possible for malicious websites to crash Konqueror and possibly other applications with rely on KJS. The KDE JavaScript implementation, KJS has been found to crash when it tries to read the contents of an FTP iframe. This can be demonstrated by creating a web page with an iframe with a src of "ftp://localhost/anything", then reading the contents of this iframe with JavaScript similar to the following. (A working FTP server is not required). document.getElementById(iframe_name).contentWindow.document.body.innerHTML; || Problem Packages =================== - ------------------------------------------------------------------ Package | Repo | Group | Unsafe | Safe | - ------------------------------------------------------------------ kdebase extra kde <= 3.5.6-2 Only patched Package Fix =================== Patch kdebase with this patch: http://bindshell.net/advisories/konq355/konq355-patch.diff I can reproduce this crash with Konqueror in kde-base-3.5.6-2, using this exploit: http://bindshell.net/advisories/konq355/konq355-crash-demo.zip but I can't test if the patch works because I'm testing makepkg3, that have bugs which block compiling. Please, post your feedback on this. Unofficial ArchLinux Security Bug Tracker: http://jjdanimoth.netsons.org/alsw.html where I will summarize all warning. I try to make a place where we, member of community, can talk about these: http://jjdanimoth.netsons.org/flyspray/ Reference(s) =================== http://bindshell.net/advisories/konq355 Contact ================== JJDaNiMoTh < jjdanimoth AT gmail DOT com > -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF79kdcJj0HNhER0MRAlN4AJ49RelDh4fteJLgYBpDqI3JaivmDACcCrg/ Stu4nrmA93r8TMK8m+MxHgE= =a2dp -----END PGP SIGNATURE----- _______________________________________________ arch mailing list [email protected] http://www.archlinux.org/mailman/listinfo/arch
