Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-3413
HistoryJul 19, 2012 - 12:00 a.m.

CVE-2012-3413

2012-07-1900:00:00
ubuntu.com
ubuntu.com
5

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.005 Low

EPSS

Percentile

75.2%

The HTMLQuoteColorer::process function in
messageviewer/htmlquotecolorer.cpp in KDE PIM 4.6 through 4.8 does not
disable JavaScript, Java, and Plugins, which allows remote attackers to
inject arbitrary web script or HTML via a crafted email.

Bugs

Notes

Author Note
mdeslaur caused by webkit migration, doesn’t affect natty and lower
OSVersionArchitecturePackageVersionFilename
ubuntu11.10noarchkdepim< 4:4.7.4+git111222-0ubuntu0.3UNKNOWN
ubuntu12.04noarchkdepim< 4:4.8.4a-0ubuntu0.3UNKNOWN

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.005 Low

EPSS

Percentile

75.2%