Through a malicious URL that contained a quote character it...
Vulnerability Description
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-7966
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/93360
- http://www.openwall.com/lists/oss-security/2016/10/05/1
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QNMM5TVPTJQFPJ3YDF4DPXDFW3GQLWLY/
- http://lists.opensuse.org/opensuse-updates/2016-10/msg00065.html
- http://www.debian.org/security/2016/dsa-3697
More from kde
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.