PT-2016-7450 · Kde · Kmail
CVE-2016-7967
·
Publicado
2016-12-23
·
Atualizado
2016-12-27
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
KMail versions 5.3.0 and later
Description
The issue concerns the use of a QWebEngine based viewer in KMail that has JavaScript enabled. This allows the generated HTML to be executed in the local file security context, enabling access to both remote and local URLs by default.
Recommendations
For KMail versions 5.3.0 and later, consider disabling JavaScript in the QWebEngine based viewer to minimize the risk of exploitation.
Correção
Improper Access Control
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Kmail