GtkHTML hts_fit_line() Null Pointer Dereference Lets Remote Users Crash the Application
|
|
SecurityTracker Alert ID: 1007680 |
|
SecurityTracker URL: http://securitytracker.com/id/1007680
|
|
CVE Reference:
CAN-2003-0541
(Links to External Site)
|
Date: Sep 11 2003
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): prior to 1.1.10
|
Description:
A vulnerability was reported in GtkHTML. A remote user can create an HTML message that, when processed by the GtkHTML library, may cause the application to crash.
It is reported that a malformed HTML message may be able to trigger a null pointer dereference in the hts_fit_line() function in 'htmltextslave.c'. As a result, an application that uses the GtkHTML library may crash when processing a specially crafted HTML message. The Ximian Evolution mail component is one application that is affected, according to the report.
Alan Cox is credited with discovering this flaw.
|
Impact:
A remote user can create HTML that, when processed by an application that uses GtkHTML, will cause the application to crash.
|
Solution:
The vendor released a fixed version (1.1.10) in April 2003. The fixed version is available at:
http://ftp.gnome.org/pub/GNOME/sources/gtkhtml/1.1/gtkhtml-1.1.10.tar.gz
md5sum: f84b69eb65dacfa7e8719a3879b1ca3a
size: 1.4M
http://ftp.gnome.org/pub/GNOME/sources/gtkhtml/1.1/gtkhtml-1.1.10.tar.bz2
md5sum: 8647407560e4b61ba4a12653b9cc8869
size: 1012k
|
Vendor URL: cvs.gnome.org/lxr/source/gtkhtml2/ChangeLog (Links to External Site)
|
Cause:
Boundary error
|
Underlying OS:
Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Thu, 11 Sep 2003 02:14:59 -0400
Subject: CVE CAN-2003-0541
|
Red Hat reported in RHSA-2003:264-01 that there is a vulnerability in versions of GtkHTML
prior to 1.1.10. According to the report, malformed HTML messages may be able to cause
the Evolution mail component to crash due to a null pointer dereference in
the GtkHTML library.
CVE: CAN-2003-0541
|
|