CVE-2011-1168

Publication date 11 April 2011

Last updated 24 July 2024


Ubuntu priority

Cross-site scripting (XSS) vulnerability in the KHTMLPart::htmlError function in khtml/khtml_part.cpp in Konqueror in KDE SC 4.4.0 through 4.6.1 allows remote attackers to inject arbitrary web script or HTML via the URI in a URL corresponding to an unavailable web site.

Status

Package Ubuntu Release Status
kde4libs 10.10 maverick
Fixed 4:4.5.1-0ubuntu8.1
10.04 LTS lucid
Fixed 4:4.4.5-0ubuntu1.1
9.10 karmic
Fixed 4:4.3.2-0ubuntu7.3
8.04 LTS hardy Ignored end of life
6.06 LTS dapper Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
kde4libs

References

Related Ubuntu Security Notices (USN)

    • USN-1110-1
    • KDE-Libs vulnerabilities
    • 14 April 2011

Other references