CVE-2012-3413: Medium severity KDE KDE PIM vulnerability
Published Aug 7, 2012
·Updated
The HTMLQuoteColorer::process function in messageviewer/htmlquotecolorer.cpp in KDE PIM 4.6 through 4.8 does not disable JavaScript, Java, and Plugins, which allows remote attackers to inject arbitrary web script or HTML via a crafted email.
Affected Software
2 affected components
KDE KDE PIM=4.6
KDE KDE PIM=4.8
Event History
Aug 7, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3413?
CVE-2012-3413 is considered a medium severity vulnerability due to the potential for remote script injection.
2
How do I fix CVE-2012-3413?
To fix CVE-2012-3413, users should update to a patched version of KDE PIM that disables JavaScript, Java, and Plugins.
3
What types of software are affected by CVE-2012-3413?
CVE-2012-3413 affects KDE PIM versions 4.6 through 4.8.
4
What kind of attack can occur due to CVE-2012-3413?
CVE-2012-3413 allows remote attackers to inject arbitrary web scripts or HTML via crafted emails.
5
Who can exploit CVE-2012-3413?
Any remote attacker can exploit CVE-2012-3413 if the affected software is used to view crafted emails.