KDE Buffer Overflow in KHTML PNG Loader May Let Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1019929
|
|
SecurityTracker URL: http://securitytracker.com/id?1019929
|
|
CVE Reference: CVE-2008-1670
(Links to External Site)
|
Date: Apr 28 2008
|
Impact: Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): 4.0 and later versions
|
Description: A vulnerability was reported in KDE KHTML. A remote user may be able to cause arbitrary code to be executed on the target user's system.
A remote user can create a specially crafted PNG image file that, when loaded by the target user, will trigger a heap overflow in
the PNG image loader and potentially execute arbitrary code on the target system. The code will run with the privileges of the
target user.
KDE 3.x is not affected.
Matt Rogers reported this vulnerability.
|
Impact: A remote user can create an image file that, when loaded by the target user, may execute arbitrary code on the target user's system.
|
Solution: The vendor has issued a patch for KDE 4.0 and later, available at:
ftp://ftp.kde.org/pub/kde/security_patches
f31a4bb0429149e27b4436f138eea471
post-kde-4.0.3-khtml.diff
The vendor's advisory is available at:
http://www.kde.org/info/security/advisory-20080426-1.txt
|
Vendor URL: www.kde.org/info/security/advisory-20080426-1.txt (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Linux (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Mon, 28 Apr 2008 08:13:53 -0400
Subject: KDE
|
KDE Security Advisory: KHTML PNG Loader Buffer Overflow
Original Release Date: 2008-04-26
URL: http://www.kde.org/info/security/advisory-20080426-1.txt
0. References
CVE-2008-1670
http://bugs.kde.org/show_bug.cgi?id=156623
1. Systems affected:
KHTML, as shipped with KDE 4.0 or newer. KDE 3.x is not affected.
2. Overview:
The new progressive PNG Image loader in KHTML of KDE 4.0 and newer
can be tricked into overrunning a heap allocated memory buffer
by loading a specially encoded image.
3. Impact:
A remote site can cause a denial of service and possibly execute
arbitrary code in the context of the user.
4. Solution:
Source code patches have been made available which fix these
vulnerabilities. Contact your OS vendor / binary package provider
for information about how to obtain updated binary packages.
5. Patch:
A patch for KDE 4.0 and newer is available from
ftp://ftp.kde.org/pub/kde/security_patches :
f31a4bb0429149e27b4436f138eea471 post-kde-4.0.3-khtml.diff
|
|