PT-2016-7451 · Kde · Kmail

Published

2016-12-23

·

Updated

2016-12-27

·

CVE-2016-7968

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions KMail versions 5.3.0 and later
Description The issue concerns the execution of JavaScript code in HTML mail contents. Since version 5.3.0, KMail has used a QWebEngine based viewer with JavaScript enabled, but it did not sanitize HTML mail contents for JavaScript, allowing included code to be executed.
Recommendations For KMail versions 5.3.0 and later, consider disabling JavaScript execution in the QWebEngine based viewer as a temporary workaround until a patch is available.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-7968

Affected Products

Kmail