oss-sec mailing list archives

Re: CVE Request: KDE Pim


From: Tomas Hoger <thoger () redhat com>
Date: Tue, 17 Jul 2012 15:35:27 +0200

On Tue, 17 Jul 2012 14:06:40 +0200 David Faure wrote:

On Tuesday 17 July 2012 10:18:06 laurent Montel wrote:
Security problem is that we allows to use javascript.
In 4.4 we don't have it.

And here's a testcase for the actual bug.
In kmail, Ctrl+O, open this .mbox, click on the HTML version, enable
HTML rendering, a javascript messagebox pops up.
Not sure what can really be exploited here (xmlhttprequest?), but at
least this way one can prove that 4.4 isn't affected, and test the
4.9 fix.

Impact may depend on what domain is used for those scripts.  E.g. if
html attachments were treated as local files / having null domain, and
the message view was using khtml, having JS enabled would be a real
problem because of this https://bugs.kde.org/show_bug.cgi?id=235468

-- 
Tomas Hoger / Red Hat Security Response Team


Current thread: