USN-245-1: KDE library vulnerability
20 January 2006
KDE library vulnerability
Releases
Details
Maksim Orlovich discovered that kjs, the Javascript interpreter engine
used by Konqueror and other parts of KDE, did not sufficiently verify
the validity of UTF-8 encoded URIs. Specially crafted URIs could
trigger a buffer overflow. By tricking an user into visiting a
web site with malicious JavaScript code, a remote attacker could
exploit this to execute arbitrary code with user privileges.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 5.10
-
kdelibs4c2
-
Ubuntu 5.04
-
kdelibs4c2
-
In general, a standard system update will make all the necessary changes.