CVE-2006-7139: Input Validation
Published Mar 7, 2007
·Updated
Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, allows remote attackers to cause a denial of service (crash) via an HTML e-mail with certain table and frameset tags that trigger a segmentation fault, possibly involving invalid free or delete operations.
Affected Software
2 affected components
KDE kde=3.5.2
KDE K-Mail=1.9.1
Event History
Mar 7, 2007
CVE Published
08:19 PM
Data Sourced
08:19 PM
DescriptionWeaknessAffected Software
Mar 8, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-7139?
CVE-2006-7139 is classified as a denial of service vulnerability that can crash Kmail.
2
How do I fix CVE-2006-7139?
The recommended fix for CVE-2006-7139 is to upgrade to a version of Kmail that does not have this vulnerability.
3
Which versions of Kmail are affected by CVE-2006-7139?
CVE-2006-7139 affects Kmail version 1.9.1 when used with KDE version 3.5.2.
4
What attack vector does CVE-2006-7139 exploit?
CVE-2006-7139 exploits the handling of certain HTML table and frameset tags in emailed content.
5
How does CVE-2006-7139 cause a denial of service?
CVE-2006-7139 causes a denial of service by triggering a segmentation fault through malformed HTML content.