First published: Fri Dec 23 2016(Updated: )
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KMail | <=5.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7967 is rated as a medium severity vulnerability due to the potential for JavaScript execution risks.
To mitigate CVE-2016-7967, update KMail to version 5.3.1 or later, which disables JavaScript in the QWebEngine viewer.
CVE-2016-7967 affects KMail versions up to and including 5.3.0.
CVE-2016-7967 allows execution of both local and remote URLs, which can lead to potential data exposure or system compromise.
As a workaround for CVE-2016-7967, users can disable JavaScript in their email settings if using an affected version of KMail.