CVE-2009-1687
kde4libs - several vulnerabilities
EPSS 7.8%
Description
The JavaScript garbage collector in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle allocation failures, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document that triggers write access to an "offset of a NULL pointer."
How to fix CVE-2009-1687
To remediate CVE-2009-1687, upgrade the affected package to a fixed version below.
- Debian/kde4libs—upgrade to 4:4.1.0-3+lenny1 or later
- —upgrade to 4:4.5.2-1 or later
Is CVE-2009-1687 being exploited?
Moderate — EPSS is 7.8%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 4:4.1.0-3+lenny1
- from 0, < 4:4.5.2-1