LWN.net Logo

kdebase-runtime: missing input validation

Package(s):kdebase-runtime CVE #(s):
Created:December 11, 2009 Updated:December 16, 2009
Description: From the Ubuntu advisory: It was discovered that the KIO subsystem of KDE did not properly perform input validation when processing help:// URIs. If a user or KIO application processed a crafted help:// URI, an attacker could trigger JavaScript execution or access files via directory traversal.
Alerts:
Ubuntu USN-872-1 2009-12-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds