lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  PHC 
Open Source and information security mailing list archives
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Sun, 04 Mar 2007 21:38:01 +0000
From: mark <>
Subject: Konqueror DoS Via JavaScript Read Of FTP Iframe


Konqueror crashes if JavaScript code tries to read the source of a child
iframe which is set to an ftp:// URL.


It is possible for malicious websites to crash Konqueror and possibly
other applications with rely on KJS.


The KDE JavaScript implementation, KJS has been found to crash when it
tries to read the contents of an FTP iframe.  This can be demonstrated
by creating a web page with an iframe with a src of
"ftp://localhost/anything", then reading the contents of this iframe
with JavaScript similar to the following.  (A working FTP server is not

var contents =


Proof of concept code is available at:

Vulnerable Versions

This vulnerability has been tested on Gentoo and Debian running KDE 3.5.5.

Reported By

Disclosure Timeline

2007-02-03  Vulnerability reported to
2007-02-28  KDE team recreate bug and produce preliminary patch for
2007-03-01  KDE team produced updated patch for ecma/kjs_html.cpp
2007-03-04  Public advisory released

Patch Information

The latest patch received from the KDE team is available from:

Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia -

Powered by blists - more mailing lists