CVE-2009-1725
Published: 9 July 2009
WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
Notes
Author | Note |
---|---|
jdstrand | webkit is a fork of khtml from kdelibs. kdelibs5 is farther from it, while qt4-x11 attempts to unify khtml and webkit |
mdeslaur | PoC: http://trac.webkit.org/browser/trunk/LayoutTests/fast/parser/eightdigithexentity.html?rev=44799&format=txt expected output: http://trac.webkit.org/browser/trunk/LayoutTests/fast/parser/eightdigithexentity-expected.txt?rev=44799&format=txt direct link: http://trac.webkit.org/export/46476/trunk/LayoutTests/fast/parser/eightdigithexentity.html as per RH bug, in kde4libs, this is a rendering bug, not a security bug |
Priority
Status
Package | Release | Status |
---|---|---|
webkit Launchpad, Ubuntu, Debian |
upstream |
Needs triage
|
dapper |
Does not exist
|
|
hardy |
Ignored
(end of life)
|
|
intrepid |
Released
(1.0.1-2ubuntu0.2)
|
|
jaunty |
Released
(1.0.1-4ubuntu0.1)
|
|
karmic |
Not vulnerable
(1.1.14-1ubuntu1)
|
|
lucid |
Not vulnerable
(1.1.14-1ubuntu1)
|
|
maverick |
Not vulnerable
(1.1.14-1ubuntu1)
|
|
natty |
Not vulnerable
(1.1.14-1ubuntu1)
|
|
Patches: upstream: http://trac.webkit.org/changeset/44799 |
||
kde4libs Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Ignored
|
|
intrepid |
Ignored
|
|
jaunty |
Ignored
|
|
karmic |
Ignored
|
|
lucid |
Ignored
|
|
maverick |
Ignored
|
|
natty |
Ignored
|
|
upstream |
Needs triage
|
|
Patches: upstream: http://websvn.kde.org/?view=rev&revision=1002162 (trunk) upstream: http://websvn.kde.org/?view=rev&revision=1002163 (4.3) |
||
kdelibs Launchpad, Ubuntu, Debian |
dapper |
Ignored
|
hardy |
Ignored
|
|
intrepid |
Ignored
|
|
jaunty |
Ignored
|
|
karmic |
Ignored
|
|
lucid |
Ignored
|
|
maverick |
Ignored
|
|
natty |
Ignored
|
|
upstream |
Needs triage
|
|
Patches: upstream: http://websvn.kde.org/?view=rev&revision=1002164 (3.5) |
||
qt4-x11 Launchpad, Ubuntu, Debian |
dapper |
Not vulnerable
(no webkit)
|
hardy |
Not vulnerable
(no webkit)
|
|
intrepid |
Released
(4.4.3-0ubuntu1.4)
|
|
jaunty |
Released
(4.5.0-0ubuntu4.3)
|
|
karmic |
Ignored
(end of life)
|
|
lucid |
Not vulnerable
(4:4.6.1-1ubuntu2)
|
|
maverick |
Not vulnerable
(4:4.6.1-1ubuntu2)
|
|
natty |
Not vulnerable
(4:4.6.1-1ubuntu2)
|
|
upstream |
Needs triage
|