Name | CVE-2008-3632 |
Description | Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a web page with crafted Cascading Style Sheets (CSS) import statements. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 499771, 561760 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|
qt4-x11 | source | (unstable) | 4:4.6.2-4 | | | 561760 |
webkit | source | (unstable) | 1.0.1-4 | | | 499771 |
Notes
[lenny] - qt4-x11 <no-dsa> (Minor impact, no apps in Lenny which use qtwebkit )
QT4 might be fixed earlier, but only 4.6.2 was checked against, Lenny is affected
http://trac.webkit.org/changeset/34815