USN-3100-1: KDE-PIM Libraries vulnerability
USN-3100-1: KDE-PIM Libraries vulnerability Ubuntu Security Notice USN-3100-1 12th October, 2016 kdepimlibs vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary KMail could be made to run HTML if it opened a specially crafted email. Software description kdepimlibs – the KDE PIM libraries Details Roland Tapken discovered that the KDE-PIM Libraries incorrectly filteredURLs. A remote attacker could use this issue to perform an HTML injectionattack in the KMail plain text viewer. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: libkpimutils4 4:4.8.5-0ubuntu0.3 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to restart KMail to make all thenecessary changes. References CVE-2016-7966 Source: USN-3100-1: KDE-PIM Libraries vulnerability