CVE-2009-1712

NameCVE-2009-1712
DescriptionWebKit in Apple Safari before 4.0 does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gain privileges, or obtain sensitive information via an APPLET or OBJECT element.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-1950-1, DSA-1988-1
Debian Bugs535793

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
kde4libs (PTS)buster4:4.14.38-3fixed
qt4-x11 (PTS)buster4:4.8.7+dfsg-18+deb10u1fixed
buster (security)4:4.8.7+dfsg-18+deb10u2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kde4libssource(unstable)(not affected)
kdelibssource(unstable)(not affected)
qt4-x11sourceetch(not affected)
qt4-x11sourcelenny4.4.3-1+lenny1DSA-1988-1
qt4-x11source(unstable)4:4.5.2-2
webkitsourcelenny1.0.1-4+lenny2DSA-1950-1
webkitsource(unstable)1.1.12-1medium535793

Notes

[etch] - qt4-x11 <not-affected> (QTWebkit was introduced in 4.4)
http://trac.webkit.org/changeset/41568

Search for package or bug name: Reporting problems