CVE-2007-1308

Publication date 7 March 2007

Last updated 24 July 2024


Ubuntu priority

ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessing the content of an iframe with an ftp:// URI in the src attribute, probably due to a NULL pointer dereference.

Status

Package Ubuntu Release Status
kdelibs 7.04 feisty
Fixed 3.5.6-0ubuntu14.1
6.10 edgy
Fixed 3.5.5-0ubuntu3.5
6.06 LTS dapper
Fixed 3.5.2-0ubuntu18.5

References

Related Ubuntu Security Notices (USN)

    • USN-447-1
    • KDE library vulnerabilities
    • 29 March 2007

Other references