CVE-2016-7967: Code Injection
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7967?
CVE-2016-7967 is rated as a medium severity vulnerability due to the potential for JavaScript execution risks.
How do I fix CVE-2016-7967?
To mitigate CVE-2016-7967, update KMail to version 5.3.1 or later, which disables JavaScript in the QWebEngine viewer.
What versions of KMail are affected by CVE-2016-7967?
CVE-2016-7967 affects KMail versions up to and including 5.3.0.
What risks are associated with CVE-2016-7967?
CVE-2016-7967 allows execution of both local and remote URLs, which can lead to potential data exposure or system compromise.
Is there a workaround for CVE-2016-7967?
As a workaround for CVE-2016-7967, users can disable JavaScript in their email settings if using an affected version of KMail.