CVE-2012-4512
published 2020-02-08CVE-2012-4512: The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a…
PriorityP354high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
11.66%
95.6th percentile
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| kde | kde | — | — |
| kde | konqueror | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kdelibs: Heap-based buffer overflow when parsing location of a font face source
vendor_redhat·2012-10-30·CVSS 8.8
CVE-2012-4512 [HIGH] CWE-122 kdelibs: Heap-based buffer overflow when parsing location of a font face source
kdelibs: Heap-based buffer overflow when parsing location of a font face source
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
A heap-based buffer overflow flaw was found in the way the CSS parser of the Document Object Model's (DOM) implementation of KDE libraries performed processing of a location of a particular font face source. A remote attacker with privileges could provide a specially-crafted web page that, when opened in an application linked against KDE libraries, would lead to the application crashing or potential execution of arbitrary code.
Package: kdelibs (Red Hat Enterprise Linux 5) - Not affected
GHSA
GHSA-8m6q-hj66-2cmr: The CSS parser (khtml/css/cssparser
ghsa_unreviewed·2022-04-23
CVE-2012-4512 [MEDIUM] CWE-843 GHSA-8m6q-hj66-2cmr: The CSS parser (khtml/css/cssparser
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
No detection rules found.
http://archives.neohapsis.com/archives/bugtraq/2012-11/0005.htmlhttp://em386.blogspot.com/2010/12/webkit-css-type-confusion.htmlhttp://quickgit.kde.org/index.php?p=kdelibs.git&a=commitdiff&h=a872c8a969a8bd3706253d6ba24088e4f07f3352http://rhn.redhat.com/errata/RHSA-2012-1416.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1418.htmlhttp://secunia.com/advisories/51097http://secunia.com/advisories/51145http://www.nth-dimension.org.uk/pub/NDSA20121010.txt.aschttp://www.openwall.com/lists/oss-security/2012/10/11/11http://www.openwall.com/lists/oss-security/2012/10/30/6http://www.securitytracker.com/id?1027709http://archives.neohapsis.com/archives/bugtraq/2012-11/0005.htmlhttp://em386.blogspot.com/2010/12/webkit-css-type-confusion.htmlhttp://quickgit.kde.org/index.php?p=kdelibs.git&a=commitdiff&h=a872c8a969a8bd3706253d6ba24088e4f07f3352http://rhn.redhat.com/errata/RHSA-2012-1416.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1418.htmlhttp://secunia.com/advisories/51097http://secunia.com/advisories/51145http://www.nth-dimension.org.uk/pub/NDSA20121010.txt.aschttp://www.openwall.com/lists/oss-security/2012/10/11/11http://www.openwall.com/lists/oss-security/2012/10/30/6http://www.securitytracker.com/id?1027709
2020-02-08
Published