Bug 225420

Summary: CVE-2007-0537 Konqueror improper HTML comment rendering
Product: [Fedora] Fedora Reporter: Josh Bressers <bressers>
Component: kdelibsAssignee: Than Ngo <than>
Status: CLOSED ERRATA QA Contact: Ben Levenson <benl>
Severity: medium Docs Contact:
Priority: medium    
Version: 6Keywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: reported=20070130,source=CVE,impact=moderate,public=20070124,versions=fc5:fc6
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-03-28 14:19:58 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 229606    

Description Josh Bressers 2007-01-30 15:35:46 UTC
+++ This bug was initially created as a clone of Bug #225414 +++

A flaw was reported in the way Konqueror processes HTML which contains a comment
used in a certain manner.  It is possible to conduct a cross site scripting flaw
on sites that allow a user to enter HTML comments, which Konqueror will then
parse incorrectly, causing the site to display unintended content.

-- Additional comment from bressers on 2007-01-30 10:25 EST --
Created an attachment (id=146918)
Demo HTML file.  This file should not display an alert dialog.

This flaw also affects FC5

Comment 1 Than Ngo 2007-03-28 14:20:55 UTC
it's fixed in kdelibs-3.5.6-0.3.fc6