PT-2016-7450 · Kde · Kmail

CVE-2016-7967

·

Publicado

2016-12-23

·

Atualizado

2016-12-27

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions KMail versions 5.3.0 and later
Description The issue concerns the use of a QWebEngine based viewer in KMail that has JavaScript enabled. This allows the generated HTML to be executed in the local file security context, enabling access to both remote and local URLs by default.
Recommendations For KMail versions 5.3.0 and later, consider disabling JavaScript in the QWebEngine based viewer to minimize the risk of exploitation.

Correção

Improper Access Control

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-7967

Produtos afetados

Kmail