PT-2012-4696 · Kde · Kdepim

David

·

Published

2012-08-07

·

Updated

2012-08-08

·

CVE-2012-3413

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions KDE PIM versions 4.6 through 4.8
Description The issue concerns the HTMLQuoteColorer::process function in messageviewer/htmlquotecolorer.cpp, which fails to disable JavaScript, Java, and Plugins. This allows remote attackers to inject arbitrary web script or HTML via a crafted email.
Recommendations For KDE PIM versions 4.6 through 4.8, consider disabling the HTMLQuoteColorer::process function until a patch is available. Restrict access to email messages that may contain malicious content to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3413

Affected Products

Kdepim