Hide Forgot
CVE-2009-1724 was originally given to a Safari Webkit issue: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to parent and top objects. According to two Debian bug reports ([1], [2]) this may affect qt4 and webkit, which means it may also affect kdelibs. I am unable to find any patches for qt4 or webkit as of yet. [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538403 (qt4-x11) [2] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538402 (webkit)
Official statement from Red Hat Security Response Team regarding this issue: ---------------------------------------------------------------------------- Not vulnerable. This issue did not affect the versions of the kdelibs package, as shipped with Red Hat Enterprise Linux 3, 4, or 5.