Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by accessing an iframe when it is being updated.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://secunia.com/advisories/51145 | third party advisory vendor advisory |
http://www.nth-dimension.org.uk/pub/NDSA20121010.txt.asc | exploit |
http://www.openwall.com/lists/oss-security/2012/10/11/11 | mailing list |
http://archives.neohapsis.com/archives/bugtraq/2012-11/0005.html | mailing list |
http://quickgit.kde.org/index.php?p=kdelibs.git&a=commitdiff&h=4f2eb356f1c23444fff2cfe0a7ae10efe303d6d8 | exploit |
http://www.openwall.com/lists/oss-security/2012/10/30/6 | mailing list |
http://secunia.com/advisories/51097 | third party advisory vendor advisory |