Bug 525788 - CVE-2009-3384 WebKit, qt: Multiple security issues while handling FTP directory listings
CVE-2009-3384 WebKit, qt: Multiple security issues while handling FTP directo...
Status: CLOSED CURRENTRELEASE
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
urgent Severity urgent
: ---
: ---
Assigned To: Red Hat Product Security
impact=critical,source=upstream,repor...
: Security
: 525794 (view as bug list)
Depends On: 538235 549881 572756 572757 572758
Blocks:
  Show dependency treegraph
 
Reported: 2009-09-25 14:15 EDT by Jan Lieskovsky
Modified: 2012-07-17 20:40 EDT (History)
6 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2012-03-07 01:35:15 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)

  None (edit)
Description Jan Lieskovsky 2009-09-25 14:15:59 EDT
Multiple security flaws (integer underflow, invalid pointer dereference,
buffer underflow and a denial of service) were found in the way WebKit's
FTP parser used to process remote FTP directory listings. If a remote
FTP server issued a specially-crafted FTP command, it could lead to
disclosure of sensitive information, denial of service (application crash) or,
potentially to execution of arbitrary code, once the command was parsed.

Upstream bug report:
--------------------
https://bugs.webkit.org/show_bug.cgi?id=29294

Upstream patch:
---------------
http://trac.webkit.org/changeset/48725

Credit:
-------
Michal Zalewski
Comment 1 Jan Lieskovsky 2009-09-25 14:52:27 EDT
This issue affects latest versions of WebKit package, as shipped with
Fedora release of 10 and 11 (WebKit-1.1.0-0.16.svn40351.fc10 and WebKit-1.1.1-1.fc11). 

This issue affects latest versions of qt package, as shipped with
Fedora release of 10 and 11 (qt-4.5.2-3.fc10 and qt-4.5.2-3.fc11).
Comment 5 Fedora Update System 2009-11-13 08:45:30 EST
qt-4.5.3-9.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/qt-4.5.3-9.fc12
Comment 6 Fedora Update System 2009-11-13 22:30:24 EST
qt-4.5.3-9.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 7 Fedora Update System 2009-11-13 22:30:42 EST
qt-4.5.3-9.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 8 Fedora Update System 2009-11-13 22:33:28 EST
qt-4.5.3-9.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 12 Vincent Danen 2009-11-20 13:14:45 EST
This issue does not affect kdelibs or qt3 as provided with Red Hat Enterprise Linux 3, 4, or 5.

QtWebKit was introduced in Qt version 4, and kdelibs would not use this code for Konqueror as it uses the FTP KIO slave.
Comment 22 Huzaifa S. Sidhpurwala 2012-03-07 01:35:15 EST
This flaw was resolved in the version of webkitgtk shipped with Red Hat Enterprise Linux 6.0

Note You need to log in before you can comment on or make changes to this bug.