|
|
Log in / Subscribe / Register

kdegraphics: multiple vulnerabilities

Package(s):kdegraphics CVE #(s):CVE-2009-0945 CVE-2009-1709
Created:June 25, 2009 Updated:January 25, 2011
Description: kdegraphics has multiple vulnerabilities. From the Red Hat alert: A use-after-free flaw was found in the KDE KSVG animation element implementation. A remote attacker could create a specially-crafted SVG image, which once opened by an unsuspecting user, could cause a denial of service (Konqueror crash) or, potentially, execute arbitrary code with the privileges of the user running Konqueror. (CVE-2009-1709) A NULL pointer dereference flaw was found in the KDE, KSVG SVGList interface implementation. A remote attacker could create a specially-crafted SVG image, which once opened by an unsuspecting user, would cause memory corruption, leading to a denial of service (Konqueror crash). (CVE-2009-0945)
Alerts:
SUSE SUSE-SR:2011:002 ed, evince, hplip, libopensc2/opensc, libsmi, libwebkit, perl, python, sssd, sudo, wireshark 2011-01-25
openSUSE openSUSE-SU-2011:0024-1 webkit 2011-01-12
openSUSE openSUSE-SU-2010:1035-1 kdegraphics3 2010-12-09
Mandriva MDVSA-2010:182 kdegraphics 2010-09-14
Debian DSA-1988-1 qt4-x11 2010-02-02
Mandriva MDVSA-2010:027 kdelibs4 2010-01-27
Debian DSA-1950 webkit 2009-12-12
Mandriva MDVSA-2009:331 kdegraphics 2009-12-10
Ubuntu USN-836-1 webkit 2009-09-23
Ubuntu USN-823-1 kdegraphics 2009-08-24
Ubuntu USN-822-1 kde4libs, kdelibs 2009-08-24
Debian DSA-1866-1 kdegraphics 2009-08-19
Ubuntu USN-857-1 qt4-x11 2009-11-10
Fedora FEDORA-2009-8049 kdelibs 2009-07-27
Fedora FEDORA-2009-8039 kdelibs 2009-07-27
Fedora FEDORA-2009-6166 webkitgtk 2009-06-15
CentOS CESA-2009:1130 kdegraphics 2009-06-26
Red Hat RHSA-2009:1130-01 kdegraphics 2009-06-25

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds