First published: Fri Dec 23 2016(Updated: )
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KDE KMail | <=4.4.0 | |
Debian Debian Linux | =8.0 | |
Fedoraproject Fedora | =25 | |
SUSE Linux Enterprise | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.