oss-sec mailing list archives
Re: CVE Request: KDE Pim
From: Tomas Hoger <thoger () redhat com>
Date: Tue, 17 Jul 2012 15:35:27 +0200
On Tue, 17 Jul 2012 14:06:40 +0200 David Faure wrote:
On Tuesday 17 July 2012 10:18:06 laurent Montel wrote:Security problem is that we allows to use javascript. In 4.4 we don't have it.And here's a testcase for the actual bug. In kmail, Ctrl+O, open this .mbox, click on the HTML version, enable HTML rendering, a javascript messagebox pops up. Not sure what can really be exploited here (xmlhttprequest?), but at least this way one can prove that 4.4 isn't affected, and test the 4.9 fix.
Impact may depend on what domain is used for those scripts. E.g. if html attachments were treated as local files / having null domain, and the message view was using khtml, having JS enabled would be a real problem because of this https://bugs.kde.org/show_bug.cgi?id=235468 -- Tomas Hoger / Red Hat Security Response Team
Current thread:
- CVE Request: KDE Pim Marc Deslauriers (Jul 13)
- Re: CVE Request: KDE Pim Kurt Seifried (Jul 13)
- Re: CVE Request: KDE Pim Vincent Danen (Jul 16)
- Re: CVE Request: KDE Pim laurent Montel (Jul 17)
- Re: CVE Request: KDE Pim David Faure (Jul 17)
- Re: CVE Request: KDE Pim Tomas Hoger (Jul 17)
- Re: CVE Request: KDE Pim Vincent Danen (Jul 17)
- Re: CVE Request: KDE Pim Kurt Seifried (Jul 17)
- Re: CVE Request: KDE Pim David Faure (Jul 17)
- Re: CVE Request: KDE Pim Vincent Danen (Jul 16)
- Re: CVE Request: KDE Pim Kurt Seifried (Jul 13)