First published: Wed Mar 07 2007(Updated: )
Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, allows remote attackers to cause a denial of service (crash) via an HTML e-mail with certain table and frameset tags that trigger a segmentation fault, possibly involving invalid free or delete operations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KDE Kde Beta 3 | =3.5.2 | |
KMail | =1.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-7139 is classified as a denial of service vulnerability that can crash Kmail.
The recommended fix for CVE-2006-7139 is to upgrade to a version of Kmail that does not have this vulnerability.
CVE-2006-7139 affects Kmail version 1.9.1 when used with KDE version 3.5.2.
CVE-2006-7139 exploits the handling of certain HTML table and frameset tags in emailed content.
CVE-2006-7139 causes a denial of service by triggering a segmentation fault through malformed HTML content.