rPath Security Advisory: 2006-0195-1
Published: 2006-10-18
Products: rPath Linux 1
Rating: Major
Exposure Level Classification:
Indirect User Deterministic Unauthorized Access
Updated Versions:
kdelibs=/suppressed:devel//1/3.4.2-5.12-1
References:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4811
https://issues.rpath.com/browse/RPL-723
Description:
Previous versions of the KDE khtml library use Qt in a way that
allows unchecked pixmap image input to be provided to Qt, triggering
an integer overflow flaw in Qt. This enables a user-complicit denial
of service attack (application crash), or possibly unauthorized access
via arbitrary code execution.
Mail converted by mhonarc 2.6.15
This archive provided courtesy of JSW4.NET, Internet Hosting Services for Small Business.