PT-2016-7451 · Kde · Kmail
Publicado
2016-12-23
·
Atualizado
2016-12-27
·
CVE-2016-7968
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
KMail versions 5.3.0 and later
Description
The issue concerns the execution of JavaScript code in HTML mail contents. Since version 5.3.0, KMail has used a QWebEngine based viewer with JavaScript enabled, but it did not sanitize HTML mail contents for JavaScript, allowing included code to be executed.
Recommendations
For KMail versions 5.3.0 and later, consider disabling JavaScript execution in the QWebEngine based viewer as a temporary workaround until a patch is available.
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Kmail