Clan x86

Technical (Development, Security, etc.) => General Security Information => Topic started by: Blaze on January 22, 2006, 12:29:59 AM

Title: KDE Overflow
Post by: Blaze on January 22, 2006, 12:29:59 AM
http://it.slashdot.org/article.pl?sid=06/01/21/0936249

Quote
"An incorrect bounds check has been discovered in kjs, the JavaScript interpreter engine used by Konqueror and other parts of KDE, that allows a heap based buffer overflow when decoding specially crafted UTF-8 encoded URI sequences. It might allow malicious Javascript code to perform a heap overflow and crash Konqueror or even execute arbitrary code. Source diff patches for KDE 3.2.0 - 3.3.2 and KDE 3.4.0 - 3.5.0 are available."
Title: Re: KDE Overflow
Post by: deadly7 on January 22, 2006, 12:51:27 AM
I got a BugTraq email about that.. Neat!
Title: Re: KDE Overflow
Post by: iago on January 22, 2006, 11:27:16 AM
Luckily, KDE sucks anyway :)

By the way, you should post the patches, just in case:
QuotePatch for KDE 3.4.0 - 3.5.0 is available from
        ftp://ftp.kde.org/pub/kde/security_patches :

        ecc0ec13ce3b06e94e35aa8e937e02bf  post-3.4.3-kdelibs-kjs.diff

        Patch for KDE 3.2.0 - 3.3.2 is available from
        ftp://ftp.kde.org/pub/kde/security_patches :

        9bca9b44ca2d84e3b2f85ffb5d30e047  post-3.2.3-kdelibs-kjs.diff
Title: Re: KDE Overflow
Post by: Newby on January 22, 2006, 11:53:21 AM
/me is glad he uses FluxBox now. :)
Title: Re: KDE Overflow
Post by: deadly7 on January 22, 2006, 02:06:35 PM
Psh, XFCE!
Title: Re: KDE Overflow
Post by: Blaze on January 22, 2006, 02:23:36 PM
Quote from: deadly7 on January 22, 2006, 02:06:35 PM
Psh, XFCE!

You are very wise.
Title: Re: KDE Overflow
Post by: Joe on January 27, 2006, 10:03:15 PM
wmaker ftw.
Title: Re: KDE Overflow
Post by: iago on January 28, 2006, 03:37:38 AM
I'm going to start locking every thread that digresses into a discussion about window managers/desktop environment.  Take it somewhere else, please. 
Title: Re: KDE Overflow
Post by: deadly7 on January 28, 2006, 10:57:36 AM
Quote from: iago on January 28, 2006, 03:37:38 AM
I'm going to start locking every thread that digresses into a discussion about window managers/desktop environment.  Take it somewhere else, please. 

Moved to Unix/Linux Discussion.