Bug 840626 (CVE-2012-3413)

Summary: CVE-2012-3413 kdepim: message viewer defaults to enabling java, javascript, and plugins
Product: [Other] Security Response Reporter: Vincent Danen <vdanen>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: jreznik, kevin, ltinkl, rdieter, rnovacek, smparrish, than
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-04-11 21:42:43 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 840627    
Bug Blocks:    

Description Vincent Danen 2012-07-16 17:55:56 UTC
It was reported [1],[2] that kdepim enabled Java, JavaScript, and plugin support by default.  This could allow for the execution of Java/JavaScript or the loading of remote images in KMail's rendering of HTML email.  This has been fixed upstream [3].

The code in question looks as though it was only introduced in kdepim 4.4, which means that Red Hat Enterprise Linux 6 and earlier are not affected by this.  No CVE has been assigned as of yet.


[1] http://www.openwall.com/lists/oss-security/2012/07/13/3
[2] https://bugs.launchpad.net/ubuntu/+source/kdepim/+bug/1022690
[3] http://commits.kde.org/kdepim/dbb2f72f4745e00f53031965a9c10b2d6862bd54

Comment 1 Vincent Danen 2012-07-16 17:57:36 UTC
Created kdepim tracking bugs for this issue

Affects: fedora-all [bug 840627]

Comment 2 Vincent Danen 2012-07-16 17:58:51 UTC
I've asked upstream for confirmation as to when this was introduced:

http://www.openwall.com/lists/oss-security/2012/07/16/3

Comment 3 Than Ngo 2012-07-17 10:43:29 UTC
this issue was committed in december 2000 
https://projects.kde.org/projects/kde/kdepim/repository/revisions/a15bbe697a6f139de014309008bb23f2eb8c450c

but it's first included in 4.6.0 stable release, so this issue is not affected in rhel =< 6 but in f16,f17 and rawhide.

Comment 5 Vincent Danen 2012-07-17 16:03:04 UTC
That's right, according to upstream's response, this was added in 4.6 or 4.7:

http://www.openwall.com/lists/oss-security/2012/07/17/4


Statement:

Not vulnerable. This issue did not affect the versions of kdepim as shipped with Red Hat Enterprise Linux 5 or 6.

Comment 6 Vincent Danen 2012-07-17 19:43:53 UTC
This was assigned the name CVE-2012-3413:

http://www.openwall.com/lists/oss-security/2012/07/17/11

Comment 7 Fedora Update System 2012-07-19 08:56:43 UTC
kdepim-4.8.4-4.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2012-07-26 22:33:38 UTC
kdepim-4.8.4-4.fc16 has been pushed to the Fedora 16 stable repository.  If problems still persist, please make note of it in this bug report.