USN-2414-1: KDE-Runtime vulnerability
24 November 2014
KDE-Runtime could be made to run arbitrary javascript.
Releases
Packages
- kde-runtime - runtime components from the official KDE release
Details
Tim Brown and Darron Burton discovered that KDE-Runtime incorrectly handled
input validation. An attacker could possibly use this issue to execute
arbitrary javascript.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 12.04
After a standard system update you need to restart your session to make
all the necessary changes.