Bug 840626 (CVE-2012-3413)

Summary: CVE-2012-3413 kdepim: message viewer defaults to enabling java, javascript, and plugins
Product: [Other] Security Response Reporter: Vincent Danen <vdanen>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: jreznik, kevin, ltinkl, rdieter, rnovacek, smparrish, than
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=moderate,public=20120702,reported=20120713,source=oss-security,cvss2=5.1/AV:N/AC:H/Au:N/C:P/I:P/A:P,rhel-5/kdepim=notaffected,rhel-6/kdepim=notaffected,fedora-all/kdepim=affected
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-04-11 17:42:43 EDT Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
Bug Depends On: 840627    
Bug Blocks:    

Description Vincent Danen 2012-07-16 13:55:56 EDT
It was reported [1],[2] that kdepim enabled Java, JavaScript, and plugin support by default.  This could allow for the execution of Java/JavaScript or the loading of remote images in KMail's rendering of HTML email.  This has been fixed upstream [3].

The code in question looks as though it was only introduced in kdepim 4.4, which means that Red Hat Enterprise Linux 6 and earlier are not affected by this.  No CVE has been assigned as of yet.


[1] http://www.openwall.com/lists/oss-security/2012/07/13/3
[2] https://bugs.launchpad.net/ubuntu/+source/kdepim/+bug/1022690
[3] http://commits.kde.org/kdepim/dbb2f72f4745e00f53031965a9c10b2d6862bd54
Comment 1 Vincent Danen 2012-07-16 13:57:36 EDT
Created kdepim tracking bugs for this issue

Affects: fedora-all [bug 840627]
Comment 2 Vincent Danen 2012-07-16 13:58:51 EDT
I've asked upstream for confirmation as to when this was introduced:

http://www.openwall.com/lists/oss-security/2012/07/16/3
Comment 3 Ngo Than 2012-07-17 06:43:29 EDT
this issue was committed in december 2000 
https://projects.kde.org/projects/kde/kdepim/repository/revisions/a15bbe697a6f139de014309008bb23f2eb8c450c

but it's first included in 4.6.0 stable release, so this issue is not affected in rhel =< 6 but in f16,f17 and rawhide.
Comment 5 Vincent Danen 2012-07-17 12:03:04 EDT
That's right, according to upstream's response, this was added in 4.6 or 4.7:

http://www.openwall.com/lists/oss-security/2012/07/17/4


Statement:

Not vulnerable. This issue did not affect the versions of kdepim as shipped with Red Hat Enterprise Linux 5 or 6.
Comment 6 Vincent Danen 2012-07-17 15:43:53 EDT
This was assigned the name CVE-2012-3413:

http://www.openwall.com/lists/oss-security/2012/07/17/11
Comment 7 Fedora Update System 2012-07-19 04:56:43 EDT
kdepim-4.8.4-4.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 8 Fedora Update System 2012-07-26 18:33:38 EDT
kdepim-4.8.4-4.fc16 has been pushed to the Fedora 16 stable repository.  If problems still persist, please make note of it in this bug report.