Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2009-1725

Published: 9 July 2009

WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.

Notes

AuthorNote
jdstrand
webkit is a fork of khtml from kdelibs. kdelibs5 is farther from
it, while qt4-x11 attempts to unify khtml and webkit
mdeslaur
PoC: http://trac.webkit.org/browser/trunk/LayoutTests/fast/parser/eightdigithexentity.html?rev=44799&format=txt
expected output: http://trac.webkit.org/browser/trunk/LayoutTests/fast/parser/eightdigithexentity-expected.txt?rev=44799&format=txt
direct link: http://trac.webkit.org/export/46476/trunk/LayoutTests/fast/parser/eightdigithexentity.html
as per RH bug, in kde4libs, this is a rendering bug, not a security bug

Priority

Medium

Status

Package Release Status
webkit
Launchpad, Ubuntu, Debian
upstream Needs triage

dapper Does not exist

hardy Ignored
(end of life)
intrepid
Released (1.0.1-2ubuntu0.2)
jaunty
Released (1.0.1-4ubuntu0.1)
karmic Not vulnerable
(1.1.14-1ubuntu1)
lucid Not vulnerable
(1.1.14-1ubuntu1)
maverick Not vulnerable
(1.1.14-1ubuntu1)
natty Not vulnerable
(1.1.14-1ubuntu1)
Patches:



upstream: http://trac.webkit.org/changeset/44799
kde4libs
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy Ignored

intrepid Ignored

jaunty Ignored

karmic Ignored

lucid Ignored

maverick Ignored

natty Ignored

upstream Needs triage

Patches:
upstream: http://websvn.kde.org/?view=rev&revision=1002162 (trunk)
upstream: http://websvn.kde.org/?view=rev&revision=1002163 (4.3)


kdelibs
Launchpad, Ubuntu, Debian
dapper Ignored

hardy Ignored

intrepid Ignored

jaunty Ignored

karmic Ignored

lucid Ignored

maverick Ignored

natty Ignored

upstream Needs triage

Patches:


upstream: http://websvn.kde.org/?view=rev&revision=1002164 (3.5)

qt4-x11
Launchpad, Ubuntu, Debian
dapper Not vulnerable
(no webkit)
hardy Not vulnerable
(no webkit)
intrepid
Released (4.4.3-0ubuntu1.4)
jaunty
Released (4.5.0-0ubuntu4.3)
karmic Ignored
(end of life)
lucid Not vulnerable
(4:4.6.1-1ubuntu2)
maverick Not vulnerable
(4:4.6.1-1ubuntu2)
natty Not vulnerable
(4:4.6.1-1ubuntu2)
upstream Needs triage