CVE-2012-3413
Publication date 19 July 2012
Last updated 24 July 2024
Ubuntu priority
Description
The HTMLQuoteColorer::process function in messageviewer/htmlquotecolorer.cpp in KDE PIM 4.6 through 4.8 does not disable JavaScript, Java, and Plugins, which allows remote attackers to inject arbitrary web script or HTML via a crafted email.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| kdepim | 12.04 LTS precise |
Fixed 4:4.8.4a-0ubuntu0.3
|
| 11.10 oneiric |
Fixed 4:4.7.4+git111222-0ubuntu0.3
|
|
| 11.04 natty |
Not affected
|
|
| 10.04 LTS lucid |
Not affected
|
|
| 8.04 LTS hardy | Ignored end of life |
Notes
Patch details
| Package | Patch details |
|---|---|
| kdepim |
References
Related Ubuntu Security Notices (USN)
- USN-1512-1
- KDE PIM vulnerability
- 19 July 2012