kdegraphics: KSVG NULL-pointer dereference in the SVGList interface implementation (ACE)
Published May 13, 2009
9.3
HIGHCVSS 2.0
EPSS 9.32%
Description
Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome Stable before 1.0.154.65, and possibly other products allows remote attackers to execute arbitrary code via a document with a SVGPathList data structure containing a negative index in the (1) SVGTransformList, (2) SVGStringList, (3) SVGNumberList, (4) SVGPathSegList, (5) SVGPointList, or (6) SVGLengthList SVGList object, which triggers memory corruption.
Affected products
No data.
Running on/with
- 10.4.11
- 10.5.0
- 10.5.1
- 10.5.2
- 10.5.3
- 10.5.4
- 10.5.5
- 10.5.6
- 10.4.11
- 10.5.0
- 10.5.1
- 10.5.2
- 10.5.3
- 10.5.4
- 10.5.6
- n/a
- n/a
- ≤ 3.2.2
- 0.8
- 0.9
- 1.0
- 1.0
- 1.0
- 1.0.0
- 1.0.0b1
- 1.0.0b2
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.3
- 1.0.3
- 1.1
- 1.1.0
- 1.1.1
- 1.2
- 1.2.0
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.5
- 1.3
- 1.3.0
- 1.3.1
- 1.3.2
- 1.3.2
- 1.3.2
- 2
- 2.0
- 2.0.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.3
- 2.0.3
- 2.0.3
- 2.0.4
- 3
- 3.0
- 3.0.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.1
- 3.1.0
- 3.1.1
- 3.1.2
- 3.2
- 3.2.0
- 3.2.1
- 4.0
No data.
Red Hat Enterprise Linux 5
kdegraphics-7:3.5.4-13.el5_3
Fixed · RHSA-2009:1130
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kdegraphics-7:3.5.4-13.el5_3 | Fixed | RHSA-2009:1130 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (45)
- http://code.google.com/p/chromium/issues/detail?id=9019 x_refsource_CONFIRM
- http://googlechromereleases.blogspot.com/2009/05/stable-update-bug-fix.html x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2009/May/msg00000.html vendor-advisoryx_refsource_APPLEPatchVendor Advisory
- http://lists.apple.com/archives/security-announce/2009/May/msg00001.html vendor-advisoryx_refsource_APPLEPatchVendor Advisory
- http://lists.apple.com/archives/security-announce/2009/May/msg00002.html vendor-advisoryx_refsource_APPLEPatchVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/35056 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35074 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35095 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35576 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35805 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/36062 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/36461 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/36790 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/37746 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/43068 third-party-advisoryx_refsource_SECUNIA
- http://support.apple.com/kb/HT3549 x_refsource_CONFIRMPatchVendor Advisory
- http://support.apple.com/kb/HT3550 x_refsource_CONFIRM
- http://support.apple.com/kb/HT3639 x_refsource_CONFIRM
- http://www.debian.org/security/2009/dsa-1950 vendor-advisoryx_refsource_DEBIAN
- http://www.redhat.com/support/errata/RHSA-2009-1130.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/503594/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/34924 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1022207 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/USN-822-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-836-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-857-1 vendor-advisoryx_refsource_UBUNTU
- http://www.us-cert.gov/cas/techalerts/TA09-133A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2009/1297 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/1298 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/1321 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/1621 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0212 vdb-entryx_refsource_VUPEN
- http://www.zerodayinitiative.com/advisories/ZDI-09-022 x_refsource_MISC
- https://access.redhat.com/security/cve/CVE-2009-0945 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=506703 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50477 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-0945
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11584 vdb-entrysignaturex_refsource_OVAL
- https://usn.ubuntu.com/823-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2009-0945
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00303.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01177.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01196.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.