KDE Konqueror 3.5.1 and earlier allows remote attackers to cause a denial of service (application crash) by calling the replaceChild method on a DOM object, which triggers a null dereference, as demonstrated by calling document.replaceChild with a 0 (zero) argument.
Link | Tags |
---|---|
http://www.mandriva.com/security/advisories?name=MDKSA-2006:130 | vendor advisory |
http://www.osvdb.org/27058 | vdb entry exploit |
http://www.securityfocus.com/bid/18978 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27744 | vdb entry |
http://www.vupen.com/english/advisories/2006/2812 | vdb entry |
http://browserfun.blogspot.com/2006/07/mobb-14-konqueror-replacechild.html | exploit |
http://www.ubuntu.com/usn/usn-322-1 | vendor advisory |