Ubuntu Security Notice 420-1 – Jose Avila III and Robert Tasarz discovered that the KDE HTML library did not correctly parse HTML comments inside the “title” tag. By tricking a Konqueror user into visiting a malicious website, an attacker could bypass cross-site scripting protections.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/54252/USN-420-1.txt
Source: https://packetstormsecurity.com/files/54252/Ubuntu-Security-Notice-420-1.html

