Vulnerability Name: | CVE-2012-3413 (CCN-76937) | ||||||||||||
Assigned: | 2012-07-02 | ||||||||||||
Published: | 2012-07-02 | ||||||||||||
Updated: | 2012-08-08 | ||||||||||||
Summary: | The HTMLQuoteColorer::process function in messageviewer/htmlquotecolorer.cpp in KDE PIM 4.6 through 4.8 does not disable JavaScript, Java, and Plugins, which allows remote attackers to inject arbitrary web script or HTML via a crafted email. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-16 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2012-3413 Source: FEDORA Type: UNKNOWN FEDORA-2012-10410 Source: FEDORA Type: UNKNOWN FEDORA-2012-10411 Source: CCN Type: SA49851 KDE Kontact / KMail "HTMLQuoteColorer::process()" Security Bypass Source: SECUNIA Type: Vendor Advisory 50008 Source: UBUNTU Type: UNKNOWN USN-1512-1 Source: CCN Type: oss-sec mailing list, Fri, 13 Jul 2012 08:25:13 -0400 CVE Request: KDE Pim Source: MLIST Type: UNKNOWN [oss-security] 20120713 CVE Request: KDE Pim Source: MLIST Type: UNKNOWN [oss-security] 20120713 Re: CVE Request: KDE Pim Source: MLIST Type: UNKNOWN [oss-security] 20120716 Re: CVE Request: KDE Pim Source: MLIST Type: UNKNOWN [oss-security] 20120717 Re: CVE Request: KDE Pim Source: CCN Type: OSVDB ID: 84053 KDE Kontact / KMail messageviewer/htmlquotecolorer.cpp HTMLQuoteColorer::process() Function Email Quoted Message Handling XSS Source: CCN Type: BID-54448 Multiple KDE Products Security Bypass Vulnerability Source: CCN Type: KDE Bug 340312 Attachments are not encrypted when "automatic encryption" is selected Source: XF Type: UNKNOWN kde-htmlquotecolorerprocess-sec-bypass(76937) Source: CCN Type: KDE Projects Repository KDE Pim Revision dbb2f72f, Security fix found by David yesterday during debug Source: CONFIRM Type: UNKNOWN https://projects.kde.org/projects/kde/kdepim/repository/revisions/dbb2f72f4745e00f53031965a9c10b2d6862bd54 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |