Vulnerability Name: CVE-2007-1308 (CCN-32798) Assigned: 2007-03-04 Published: 2007-03-04 Updated: 2018-10-16 Summary: ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessing the content of an iframe with an ftp:// URI in the src attribute, probably due to a NULL pointer dereference. CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Low
CVSS v2 Severity: 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P )3.4 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P )3.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
Vulnerability Type: CWE-399 Vulnerability Consequences: Denial of Service References: Source: MISC Type: Exploit, Patch, Vendor Advisoryhttp://bindshell.net/advisories/konq355 Source: MISC Type: UNKNOWNhttp://bindshell.net/advisories/konq355/konq355-patch.diff Source: MITRE Type: CNACVE-2007-1308 Source: FULLDISC Type: Exploit, Patch20070304 Konqueror DoS Via JavaScript Read Of FTP Iframe Source: CCN Type: Full-Disclosure Mailing List, 2007-03-04 21:38:01Konqueror DoS Via JavaScript Read Of FTP Iframe Source: CCN Type: RHSA-2007-0909Moderate: kdelibs security update Source: SECUNIA Type: Vendor Advisory27108 Source: SREASON Type: UNKNOWN2345 Source: CCN Type: KDE Web siteK Desktop Environment - KDE 3.5.6 Release Announcement Source: MANDRIVA Type: UNKNOWNMDKSA-2007:054 Source: REDHAT Type: UNKNOWNRHSA-2007:0909 Source: BUGTRAQ Type: UNKNOWN20070304 Konqueror DoS Via JavaScript Read Of FTP Iframe Source: BID Type: Exploit22814 Source: CCN Type: BID-22814KDE Konqueror JavaScript IFrame Denial of Service Vulnerability Source: CCN Type: USN-447-1KDE library vulnerabilities Source: UBUNTU Type: UNKNOWNUSN-447-1 Source: VUPEN Type: UNKNOWNADV-2007-0886 Source: XF Type: UNKNOWNkonqueror-kjs-dos(32798) Source: XF Type: UNKNOWNkonqueror-ftp-dos(32798) Source: OVAL Type: UNKNOWNoval:org.mitre.oval:def:10551 Vulnerable Configuration: Configuration 1 :cpe:/a:kde:konqueror:3.5.5:*:*:*:*:*:*:* Configuration RedHat 1 :cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:* Configuration RedHat 2 :cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:* Configuration RedHat 3 :cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:* Configuration RedHat 4 :cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:* Configuration RedHat 5 :cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:* Configuration RedHat 6 :cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:* Configuration RedHat 7 :cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:* Configuration RedHat 8 :cpe:/o:redhat:enterprise_linux:5::client_workstation:*:*:*:*:* Configuration RedHat 9 :cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:* Configuration CCN 1 :cpe:/o:kde:kde:3.5.5:*:*:*:*:*:*:* AND cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:* OR cpe:/o:canonical:ubuntu:6.06::lts:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2007:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2007::x86_64:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:5:*:client_workstation:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:5:*:client:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:4.5.z::as:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:4.5.z::es:*:*:*:*:* Denotes that component is vulnerable Oval Definitions Definition ID Class Title Last Modified oval:org.mitre.oval:def:22442 P ELSA-2007:0909: kdelibs security update (Moderate) 2014-05-26 oval:org.mitre.oval:def:10551 V ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessing the content of an iframe with an ftp:// URI in the src attribute, probably due to a NULL pointer dereference. 2013-04-29 oval:com.redhat.rhsa:def:20070909 P RHSA-2007:0909: kdelibs security update (Moderate) 2008-03-20
BACK
kde konqueror 3.5.5
kde kde 3.5.5
redhat enterprise linux 4
redhat enterprise linux 4
redhat enterprise linux 4
redhat enterprise linux 4
canonical ubuntu 6.06
mandrakesoft mandrake linux 2007
mandrakesoft mandrake linux 2007
mandrakesoft mandrake linux corporate server 4.0
mandrakesoft mandrake linux corporate server 4.0
redhat enterprise linux 5
redhat enterprise linux 5
redhat enterprise linux 5
redhat enterprise linux 4.5.z
redhat enterprise linux 4.5.z