ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessing the content of an iframe with an ftp:// URI in the src attribute, probably due to a NULL pointer dereference.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Konqueror | Kde | 3.5.5 (including) | 3.5.5 (including) |
Red Hat Enterprise Linux 4 | RedHat | kdelibs-6:3.3.1-9.el4 | * |
Red Hat Enterprise Linux 5 | RedHat | kdelibs-6:3.5.4-13.el5 | * |
Kdelibs | Ubuntu | dapper | * |
Kdelibs | Ubuntu | devel | * |
Kdelibs | Ubuntu | edgy | * |
Kdelibs | Ubuntu | feisty | * |