Joined: 12 May 2004
|Posted: Sun Jan 22, 2006 1:26 pm Post subject: [ GLSA 200601-11 ] KDE kjs: URI heap overflow vulnerability
|Gentoo Linux Security Advisory
Title: KDE kjs: URI heap overflow vulnerability (GLSA 200601-11)
Date: January 22, 2006
Vulnerable: < 3.4.3-r1
Unaffected: >= 3.4.3-r1
Architectures: All supported architectures
Maksim Orlovich discovered an incorrect bounds check in kjs when handling URIs.
There is no known workaround at this time.
All kdelibs users should upgrade to the latest version:
|# emerge --sync
# emerge --ask --oneshot --verbose kde-base/kdelibs-3.4.3-r1
KDE Security Advisory: kjs encodeuri/decodeuri heap overflow vulnerability
Last edited by GLSA on Sun May 07, 2006 5:00 pm; edited 1 time in total