CVE-2009-1699

NameCVE-2009-1699
DescriptionThe XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack."
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-1988-1
Debian Bugs535793

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
kde4libs (PTS)jessie, jessie (lts)4:4.14.2-5+deb8u3fixed
stretch (lts), stretch4:4.14.26-2+deb9u1fixed
buster4:4.14.38-3fixed
qt4-x11 (PTS)jessie, jessie (lts)4:4.8.6+git64-g5dc8b2b+dfsg-3+deb8u5fixed
stretch (security)4:4.8.7+dfsg-11+deb9u3fixed
stretch (lts), stretch4:4.8.7+dfsg-11+deb9u4fixed
buster (security), buster, buster (lts)4:4.8.7+dfsg-18+deb10u2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kde4libssource(unstable)(not affected)
kdelibssource(unstable)(not affected)
qt4-x11sourceetch(not affected)
qt4-x11sourcelenny4.4.3-1+lenny1DSA-1988-1
qt4-x11source(unstable)4:4.5.2-2
webkitsource(unstable)1.0.1-4medium535793

Notes

[etch] - qt4-x11 <not-affected> (QTWebkit was introduced in 4.4)

Search for package or bug name: Reporting problems