KDE KJS Encodeuri / Decodeuri Remote Heap Overflow Vulnerability
BID:16325
Info
KDE KJS Encodeuri / Decodeuri Remote Heap Overflow Vulnerability
| Bugtraq ID: | 16325 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-0019 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 2006 12:00AM |
| Updated: | Jan 02 2007 08:11PM |
| Credit: | Maksim Orlovich discovered this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 SuSE Linux Enterprise Server 9 Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 10.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 Redhat Linux 9.0 i386 Redhat Linux 7.3 i386 Redhat Fedora Core4 Redhat Fedora Core3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Application Server ES 3 KDE kdelibs 3.4.3 KDE kdelibs 3.4 KDE KDE 3.5 KDE KDE 3.4.3 KDE KDE 3.4.2 KDE KDE 3.4.1 KDE KDE 3.4 KDE KDE 3.3.2 KDE KDE 3.3.2 KDE KDE 3.3.1 KDE KDE 3.3 KDE KDE 3.2.3 KDE KDE 3.2.2 KDE KDE 3.2.1 KDE KDE 3.2 |
| Not Vulnerable: | |
Discussion
KDE KJS Encodeuri / Decodeuri Remote Heap Overflow Vulnerability
KDE KJS is prone to a remote heap-overflow vulnerability.
Specifically, the issue presents itself when the application decodes specially crafted UTF-8 encoded URI sequences.
A successful attack can result in a remote compromise in the context of the user running the vulnerable application.
KDE versions 3.2.0, up to and including KDE 3.5.0, are vulnerable to this issue.
KDE KJS is prone to a remote heap-overflow vulnerability.
Specifically, the issue presents itself when the application decodes specially crafted UTF-8 encoded URI sequences.
A successful attack can result in a remote compromise in the context of the user running the vulnerable application.
KDE versions 3.2.0, up to and including KDE 3.5.0, are vulnerable to this issue.
Exploit / POC
KDE KJS Encodeuri / Decodeuri Remote Heap Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
KDE KJS Encodeuri / Decodeuri Remote Heap Overflow Vulnerability
Solution:
Please see the referenced advisories for more information and fixes.
KDE KDE 3.2
KDE KDE 3.2.1
KDE KDE 3.2.2
KDE KDE 3.2.3
KDE KDE 3.3
KDE KDE 3.3.1
KDE KDE 3.3.2
KDE KDE 3.3.2
KDE kdelibs 3.4
KDE KDE 3.4
KDE KDE 3.4.1
KDE KDE 3.4.2
KDE kdelibs 3.4.3
KDE KDE 3.5
Solution:
Please see the referenced advisories for more information and fixes.
KDE KDE 3.2
-
KDE post-3.2.3-kdelibs-kjs.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdelibs-kjs.diff
KDE KDE 3.2.1
-
KDE post-3.2.3-kdelibs-kjs.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdelibs-kjs.diff
KDE KDE 3.2.2
-
KDE post-3.2.3-kdelibs-kjs.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdelibs-kjs.diff
KDE KDE 3.2.3
-
KDE post-3.2.3-kdelibs-kjs.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdelibs-kjs.diff -
Slackware kdelibs-3.2.3-i486-3.tgz
Slackware 10.0:
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ kdelibs-3.2.3-i486-3.tgz
KDE KDE 3.3
-
KDE post-3.2.3-kdelibs-kjs.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdelibs-kjs.diff
KDE KDE 3.3.1
-
KDE post-3.2.3-kdelibs-kjs.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdelibs-kjs.diff
KDE KDE 3.3.2
-
Slackware kdelibs-3.3.2-i486-3.tgz
Slackware 10.1:
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/ kdelibs-3.3.2-i486-3.tgz -
Slackware kdelibs-3.4.2-i486-2.tgz
Slackware 10.2:
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/ kdelibs-3.4.2-i486-2.tgz
KDE KDE 3.3.2
-
KDE post-3.2.3-kdelibs-kjs.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.2.3-kdelibs-kjs.diff
KDE kdelibs 3.4
-
SuSE kdelibs3-3.4.0-20.10.i586.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/kdelibs3-3.4.0-20 .10.i586.rpm -
SuSE kdelibs3-3.4.0-20.10.x86_64.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/kdelibs3-3.4.0- 20.10.x86_64.rpm -
SuSE kdelibs3-32bit-9.3-7.4.x86_64.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/kdelibs3-32bit- 9.3-7.4.x86_64.rpm -
SuSE kdelibs3-devel-3.4.0-20.10.i586.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/kdelibs3-devel-3. 4.0-20.10.i586.rpm -
SuSE kdelibs3-devel-3.4.0-20.10.x86_64.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/kdelibs3-devel- 3.4.0-20.10.x86_64.rpm -
Ubuntu kdelibs-bin_3.4.0-0ubuntu3.5_amd64.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs-bin_3.4. 0-0ubuntu3.5_amd64.deb -
Ubuntu kdelibs-bin_3.4.0-0ubuntu3.5_i386.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs-bin_3.4. 0-0ubuntu3.5_i386.deb -
Ubuntu kdelibs-bin_3.4.0-0ubuntu3.5_powerpc.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs-bin_3.4. 0-0ubuntu3.5_powerpc.deb -
Ubuntu kdelibs-data_3.4.0-0ubuntu3.5_all.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs-data_3.4 .0-0ubuntu3.5_all.deb -
Ubuntu kdelibs-data_3.4.3-0ubuntu2_all.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs-data_3.4 .3-0ubuntu2_all.deb -
Ubuntu kdelibs_3.4.0-0ubuntu3.5_all.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs_3.4.0-0u buntu3.5_all.deb -
Ubuntu kdelibs4-dev_3.4.0-0ubuntu3.5_amd64.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs4-dev_3.4 .0-0ubuntu3.5_amd64.deb -
Ubuntu kdelibs4-dev_3.4.0-0ubuntu3.5_i386.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs4-dev_3.4 .0-0ubuntu3.5_i386.deb -
Ubuntu kdelibs4-dev_3.4.0-0ubuntu3.5_powerpc.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs4-dev_3.4 .0-0ubuntu3.5_powerpc.deb -
Ubuntu kdelibs4-doc_3.4.0-0ubuntu3.5_all.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs4-doc_3.4 .0-0ubuntu3.5_all.deb -
Ubuntu kdelibs4_3.4.0-0ubuntu3.5_amd64.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs4_3.4.0-0 ubuntu3.5_amd64.deb -
Ubuntu kdelibs4_3.4.0-0ubuntu3.5_i386.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs4_3.4.0-0 ubuntu3.5_i386.deb -
Ubuntu kdelibs4_3.4.0-0ubuntu3.5_powerpc.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs4_3.4.0-0 ubuntu3.5_powerpc.deb
KDE KDE 3.4
-
KDE post-3.4.3-kdelibs-kjs.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.3-kdelibs-kjs.diff
KDE KDE 3.4.1
-
KDE post-3.4.3-kdelibs-kjs.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.3-kdelibs-kjs.diff
KDE KDE 3.4.2
-
KDE post-3.4.3-kdelibs-kjs.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.3-kdelibs-kjs.diff -
SuSE kdelibs3-3.4.2-24.2.i586.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/kdelibs3-devel-3 .4.2-24.2.i586.rpm -
SuSE kdelibs3-3.4.2-24.2.ppc.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/kdelibs3-3.4.2-24 .2.ppc.rpm -
SuSE kdelibs3-3.4.2-24.2.x86_64.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/kdelibs3-3.4.2 -24.2.x86_64.rpm -
SuSE kdelibs3-32bit-3.4.2-24.2.x86_64.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/kdelibs3-32bit -3.4.2-24.2.x86_64.rpm -
SuSE kdelibs3-devel-3.4.2-24.2.i586.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/kdelibs3-devel-3 .4.2-24.2.i586.rpm -
SuSE kdelibs3-devel-3.4.2-24.2.ppc.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/kdelibs3-devel-3. 4.2-24.2.ppc.rpm -
SuSE kdelibs3-devel-3.4.2-24.2.x86_64.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/kdelibs3-devel -3.4.2-24.2.x86_64.rpm
KDE kdelibs 3.4.3
-
Ubuntu kdelibs-bin_3.4.3-0ubuntu2_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs-bin_3.4. 3-0ubuntu2_amd64.deb -
Ubuntu kdelibs-bin_3.4.3-0ubuntu2_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs-bin_3.4. 3-0ubuntu2_i386.deb -
Ubuntu kdelibs-bin_3.4.3-0ubuntu2_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs-bin_3.4. 3-0ubuntu2_powerpc.deb -
Ubuntu kdelibs-data_3.4.3-0ubuntu2_all.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs-data_3.4 .3-0ubuntu2_all.deb -
Ubuntu kdelibs_3.4.3-0ubuntu2_all.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs_3.4.3-0u buntu2_all.deb -
Ubuntu kdelibs4-dev_3.4.3-0ubuntu2_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs4-dev_3.4 .3-0ubuntu2_amd64.deb -
Ubuntu kdelibs4-dev_3.4.3-0ubuntu2_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs4-dev_3.4 .3-0ubuntu2_i386.deb -
Ubuntu kdelibs4-dev_3.4.3-0ubuntu2_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs4-dev_3.4 .3-0ubuntu2_powerpc.deb -
Ubuntu kdelibs4c2-dbg_3.4.3-0ubuntu2_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/kdelibs/kdelibs4c2-d bg_3.4.3-0ubuntu2_amd64.deb -
Ubuntu kdelibs4c2-dbg_3.4.3-0ubuntu2_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/kdelibs/kdelibs4c2-d bg_3.4.3-0ubuntu2_i386.deb -
Ubuntu kdelibs4c2-dbg_3.4.3-0ubuntu2_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/universe/k/kdelibs/kdelibs4c2-d bg_3.4.3-0ubuntu2_powerpc.deb -
Ubuntu kdelibs4c2_3.4.3-0ubuntu2_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs4c2_3.4.3 -0ubuntu2_amd64.deb -
Ubuntu kdelibs4c2_3.4.3-0ubuntu2_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs4c2_3.4.3 -0ubuntu2_i386.deb -
Ubuntu kdelibs4c2_3.4.3-0ubuntu2_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/k/kdelibs/kdelibs4c2_3.4.3 -0ubuntu2_powerpc.deb
KDE KDE 3.5
-
KDE post-3.4.3-kdelibs-kjs.diff
ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.3-kdelibs-kjs.diff