Name | CVE-2009-1712 |
Description | WebKit in Apple Safari before 4.0 does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gain privileges, or obtain sensitive information via an APPLET or OBJECT element. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-1950-1, DSA-1988-1 |
Debian Bugs | 535793 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
kde4libs (PTS) | jessie, jessie (lts) | 4:4.14.2-5+deb8u3 | fixed |
stretch | 4:4.14.26-2 | fixed | |
buster | 4:4.14.38-3 | fixed | |
qt4-x11 (PTS) | jessie, jessie (lts) | 4:4.8.6+git64-g5dc8b2b+dfsg-3+deb8u5 | fixed |
stretch (security) | 4:4.8.7+dfsg-11+deb9u3 | fixed | |
stretch (lts), stretch | 4:4.8.7+dfsg-11+deb9u4 | fixed | |
buster | 4:4.8.7+dfsg-18+deb10u1 | fixed | |
buster (security) | 4:4.8.7+dfsg-18+deb10u2 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
kde4libs | source | (unstable) | (not affected) | |||
kdelibs | source | (unstable) | (not affected) | |||
qt4-x11 | source | etch | (not affected) | |||
qt4-x11 | source | lenny | 4.4.3-1+lenny1 | DSA-1988-1 | ||
qt4-x11 | source | (unstable) | 4:4.5.2-2 | |||
webkit | source | lenny | 1.0.1-4+lenny2 | DSA-1950-1 | ||
webkit | source | (unstable) | 1.1.12-1 | medium | 535793 |
[etch] - qt4-x11 <not-affected> (QTWebkit was introduced in 4.4)
http://trac.webkit.org/changeset/41568