Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1382288 - (CVE-2016-7967) CVE-2016-7967 kdepim: JavaScript access to local and remote URLs in Kmail
CVE-2016-7967 kdepim: JavaScript access to local and remote URLs in Kmail
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20161004,repor...
: Security
Depends On: 1382296 1382297 1382298 1382299 1383610
Blocks: 1382295
  Show dependency treegraph
 
Reported: 2016-10-06 05:21 EDT by Adam Mariš
Modified: 2017-03-24 04:26 EDT (History)
8 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2017-03-24 04:26:19 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Adam Mariš 2016-10-06 05:21:43 EDT
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.

CVE assignment:

http://seclists.org/oss-sec/2016/q4/23

External References:

https://www.kde.org/info/security/advisory-20161006-2.txt
Comment 1 Adam Mariš 2016-10-06 05:32:58 EDT
Created kdepim3 tracking bugs for this issue:

Affects: fedora-all [bug 1382297]
Affects: epel-7 [bug 1382299]
Comment 2 Adam Mariš 2016-10-06 05:33:07 EDT
Created kdepim tracking bugs for this issue:

Affects: fedora-all [bug 1382296]
Comment 3 Adam Mariš 2016-10-06 05:33:14 EDT
Created kdepim4 tracking bugs for this issue:

Affects: fedora-all [bug 1382298]
Comment 4 Ngo Than 2016-10-10 09:46:42 EDT
Adam, this issue is effected in kf5-messagelib. Could you please change it to correct component?

thanks
Comment 5 Adam Mariš 2016-10-11 04:48:46 EDT
Created kf5-messagelib tracking bugs for this issue:

Affects: fedora-all [bug 1383610]
Comment 6 Adam Mariš 2016-10-11 04:51:33 EDT
(In reply to Ngo Than from comment #4)
> Adam, this issue is effected in kf5-messagelib. Could you please change it
> to correct component?

Done! Does the same apply for CVE-2016-7968?

Thanks!
Comment 7 Ngo Than 2016-10-11 08:43:18 EDT
(In reply to Adam Mariš from comment #6)
> (In reply to Ngo Than from comment #4)
> > Adam, this issue is effected in kf5-messagelib. Could you please change it
> > to correct component?
> 
> Done! Does the same apply for CVE-2016-7968?
> 
> Thanks!

yes, it's same for CVE-2016-7968
Comment 8 Fedora Update System 2016-10-30 13:54:18 EDT
kdepim-16.08.2-1.fc24, kdepim-addons-16.08.2-1.fc24, kdepim-apps-libs-16.08.2-1.fc24, kdepim-runtime-16.08.2-1.fc24, kf5-akonadi-calendar-16.08.2-1.fc24, kf5-akonadi-contacts-16.08.2-1.fc24, kf5-akonadi-mime-16.08.2-1.fc24, kf5-akonadi-notes-16.08.2-1.fc24, kf5-akonadi-search-16.08.2-1.fc24, kf5-akonadi-server-16.08.2-1.fc24, kf5-calendarsupport-16.08.2-1.fc24, kf5-eventviews-16.08.2-1.fc24, kf5-gpgmepp-16.08.2-1.fc24, kf5-grantleetheme-16.08.2-1.fc24, kf5-incidenceeditor-16.08.2-1.fc24, kf5-kalarmcal-16.08.2-1.fc24, kf5-kblog-16.08.2-1.fc24, kf5-kcalendarcore-16.08.2-1.fc24, kf5-kcalendarutils-16.08.2-1.fc24, kf5-kcontacts-16.08.2-1.fc24, kf5-kdgantt2-16.08.2-1.fc24, kf5-kholidays-16.08.2-1.fc24, kf5-kidentitymanagement-16.08.2-1.fc24, kf5-kimap-16.08.2-1.fc24, kf5-kldap-16.08.2-1.fc24, kf5-kmailtransport-16.08.2-1.fc24, kf5-kmbox-16.08.2-1.fc24, kf5-kmime-16.08.2-1.fc24, kf5-kontactinterface-16.08.2-1.fc24, kf5-kpimtextedit-16.08.2-1.fc24, kf5-ktnef-16.08.2-1.fc24, kf5-libgravatar-16.08.2-1.fc24, kf5-libkdepim-16.08.2-1.fc24, kf5-libkleo-16.08.2-1.fc24, kf5-libksieve-16.08.2-1.fc24, kf5-mailcommon-16.08.2-1.fc24, kf5-mailimporter-16.08.2-1.fc24, kf5-messagelib-16.08.2-1.fc24, kf5-pimcommon-16.08.2-1.fc24, kf5-syndication-16.08.2-1.fc24, kleopatra-16.08.2-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
Comment 9 Cedric Buissart 2017-03-24 04:26:30 EDT
Statement:

This issue did not affect the versions of kdepim as shipped with Red Hat Enterprise Linux 5, 6 and 7.

Note You need to log in before you can comment on or make changes to this bug.