Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2016-7968

Published: 23 December 2016

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.

Notes

AuthorNote
sbeattie
need QT 5.7 to disable entirely, partial sanitization commits
are linked off of the kde advisory
mdeslaur
5.3.0 and over
tyhicks
tsimonq2 says that kmail in kdepim Zesty and older is not affected
sbeattie
kmail did not use QWebSettings through zesty

Priority

Medium

Cvss 3 Severity Score

6.5

Score breakdown

Status

Package Release Status
kdepim
Launchpad, Ubuntu, Debian
precise Not vulnerable
(4:4.8.5-0ubuntu0.1)
trusty Not vulnerable
(4:4.13.3-0ubuntu0.1)
upstream Needs triage

xenial Not vulnerable

yakkety Not vulnerable

zesty Not vulnerable

kf5-messagelib
Launchpad, Ubuntu, Debian
precise Does not exist

trusty Does not exist

upstream Needs triage

xenial Does not exist

yakkety Ignored
(end of life)
zesty Not vulnerable
(code not present)
Patches:
upstream: https://cgit.kde.org/messagelib.git/commit/?id=f601f9ffb706f7d3a5893b04f067a1f75da62c99

Severity score breakdown

Parameter Value
Base score 6.5
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality Low
Integrity impact Low
Availability impact None
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N