USN-420-1: KDE library vulnerability
6 February 2007
KDE library vulnerability
Releases
Details
Jose Avila III and Robert Tasarz discovered that the KDE HTML library
did not correctly parse HTML comments inside the "title" tag. By
tricking a Konqueror user into visiting a malicious website, an attacker
could bypass cross-site scripting protections.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 6.10
-
kdelibs4c2a
-
4:3.5.5-0ubuntu3.1
Ubuntu 6.06
-
kdelibs4c2a
-
4:3.5.2-0ubuntu18.2
Ubuntu 5.10
-
kdelibs4c2
-
4:3.4.3-0ubuntu2.2
After a standard system upgrade you need to restart your session to
effect the necessary changes.