Arch Linux

Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines

Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.

REPEAT: Do NOT report bugs for outdated packages!
Tasklist

FS#6595 - Warning on kdebase

Attached to Project: Arch Linux
Opened by DaNiMoTh (DaNiMoTh) - Wednesday, 14 March 2007, 14:16 GMT
Last edited by Roman Kyrylych (Romashka) - Thursday, 15 March 2007, 13:43 GMT
Task Type Bug Report
Category Packages: Extra
Status Closed
Assigned To Tobias Powalowski (tpowa)
Architecture not specified
Severity Medium
Priority Normal
Reported Version 0.7.2 Gimmick
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

- ------------------------------------------------------------
Arch Linux Security Warning ALSW 2007-#13
- ------------------------------------------------------------

Name: kdebase
Date: 2007-03-08
Severity: Normal
Warning #: 2007-#13

- ------------------------------------------------------------

Product Background
===================
KDE ( K Desktop Environment) Base programs.

Problem Background
===================

Konqueror crashes if JavaScript code tries to read the source of a
child iframe which is set to an FTP URL.

Impact
======

It is possible for malicious websites to crash Konqueror and possibly
other applications with rely on KJS.

The KDE JavaScript implementation, KJS has been found to crash when it
tries to read the contents of an FTP iframe. This can be demonstrated
by creating a web page with an iframe with a src of
"ftp://localhost/anything", then reading the contents of this iframe
with JavaScript similar to the following. (A working FTP server is not
required).
document.getElementById(iframe_name).contentWindow.document.body.innerHTML;
||



Problem Packages
===================
Package: kdebase
Repo: extra
Group: kde
Unsafe: <= 3.5.6-3
Safe: Only Patched


Package Fix
===================

Patch kdebase with this patch:
http://bindshell.net/advisories/konq355/konq355-patch.diff

I can reproduce this crash with Konqueror in kde-base-3.5.6-3, using
this exploit:
http://bindshell.net/advisories/konq355/konq355-crash-demo.zip
but I can't test if the patch works because I'm testing makepkg3, that
have bugs which block compiling.
Please, post your feedback on this.

Unofficial ArchLinux Security Bug Tracker:
http://jjdanimoth.netsons.org/alsw.html
where I will summarize all warning.
I try to make a place where we, member of community, can talk about these:
http://jjdanimoth.netsons.org/flyspray/


Reference(s)
===================

http://bindshell.net/advisories/konq355
This task depends upon

Closed by  Tobias Powalowski (tpowa)
Friday, 16 March 2007, 17:28 GMT
Reason for closing:  Fixed
Comment by Tobias Powalowski (tpowa) - Friday, 16 March 2007, 17:27 GMT
its kdelibs and not kdebase, fixed on testing repository

Loading...