code execution when following links
Bug #332069 reported by
Jonathan Riddell
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
kdepim (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Dapper |
Fix Released
|
Undecided
|
Jamie Strandboge | ||
Gutsy |
Fix Released
|
Undecided
|
Jamie Strandboge | ||
Hardy |
Fix Released
|
Undecided
|
Jamie Strandboge | ||
Intrepid |
Fix Released
|
Undecided
|
Jamie Strandboge | ||
Jaunty |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
Binary package hint: kdepim
Upstream reported a potential security problem in kmail
Clicking on a link inside a mail in
KMail can potentially execute code without asking the user, if the link points
to a desktop file or a .exe that is associated with Wine, or similar.
This problem happens in all KMail versions.
Changed in kdepim: | |
status: | New → In Progress |
assignee: | nobody → jdstrand |
status: | New → In Progress |
assignee: | nobody → jdstrand |
status: | New → In Progress |
assignee: | nobody → jdstrand |
status: | New → In Progress |
assignee: | nobody → jdstrand |
Changed in kdepim: | |
status: | In Progress → Fix Committed |
status: | In Progress → Fix Committed |
status: | In Progress → Fix Committed |
status: | In Progress → Fix Committed |
To post a comment you must log in.
This bug was fixed in the package kdepim - 4:4.2.0-0ubuntu8
---------------
kdepim (4:4.2.0-0ubuntu8) jaunty; urgency=low
* Add kubuntu_ 02_kmail_ file_execution. diff, don't run
executable programmes from links, LP: #332069
-- Jonathan Riddell <email address hidden> Fri, 20 Feb 2009 14:40:23 +0000