PT-2016-7451 · Kde · Kmail

Publicado

2016-12-23

·

Atualizado

2016-12-27

·

CVE-2016-7968

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions KMail versions 5.3.0 and later
Description The issue concerns the execution of JavaScript code in HTML mail contents. Since version 5.3.0, KMail has used a QWebEngine based viewer with JavaScript enabled, but it did not sanitize HTML mail contents for JavaScript, allowing included code to be executed.
Recommendations For KMail versions 5.3.0 and later, consider disabling JavaScript execution in the QWebEngine based viewer as a temporary workaround until a patch is available.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-7968

Produtos afetados

Kmail