CVE-2016-7968: Code Injection
Published Dec 23, 2016
·Updated
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.
Affected Software
1 affected component
KDE kmail<=5.3.0
Event History
Dec 23, 2016
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7968?
CVE-2016-7968 is considered to have a medium severity due to the risk of JavaScript execution from untrusted HTML emails.
2
How do I fix CVE-2016-7968?
To mitigate CVE-2016-7968, upgrade KMail to a version later than 5.3.0 where the vulnerability is patched.
3
What software is affected by CVE-2016-7968?
CVE-2016-7968 affects KMail versions up to and including 5.3.0.
4
What type of attack does CVE-2016-7968 facilitate?
CVE-2016-7968 facilitates attacks that leverage untrusted HTML mail content to execute embedded JavaScript.
5
Is there a workaround for CVE-2016-7968 if I can't upgrade?
A possible workaround for CVE-2016-7968 is to disable JavaScript in QWebEngine or avoid opening untrusted HTML emails.