Login
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in KDE
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in KDE
ID: USN-1512-1
Distribution: Ubuntu
Plattformen: Ubuntu 11.10, Ubuntu 12.04 LTS
Datum: Do, 19. Juli 2012, 16:54
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3413
Applikationen: KDE Software Compilation

Originalnachricht


--===============1581896830417248054==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-PAHwS/J5TSz6QcUXczYo"


--=-PAHwS/J5TSz6QcUXczYo
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1512-1
July 19, 2012

kdepim vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10

Summary:

KDE PIM could be made to execute JavaScript if it opened a specially
crafted email.

Software Description:
- kdepim: Personal Information Management apps

Details:

It was discovered that KDE PIM html renderer incorrectly enabled
JavaScript, Java and Plugins. A remote attacker could use this flaw to send
an email with embedded JavaScript that possibly executes when opened.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
kdepim 4:4.8.4a-0ubuntu0.3

Ubuntu 11.10:
kdepim 4:4.7.4+git111222-0ubuntu0.3

After a standard system update you need to restart your session to make all
the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1512-1
CVE-2012-3413

Package Information:
https://launchpad.net/ubuntu/+source/kdepim/4:4.8.4a-0ubuntu0.3
https://launchpad.net/ubuntu/+source/kdepim/4:4.7.4+git111222-0ubuntu0.3



--ÙAHwS/J5TSz6QcUXczYo
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJQCBBxAAoJEGVp2FWnRL6T2MUP/RRsayRLCCzvL1GBvhb0YywH
mmH+CfBe7sxZJ52HqXQRiYPTc16Q+CO7g+T0gRsSHQsrWGvINJo12zrJ9IKGBImi
BkI7ycJVw1bIs30OnoSYhGMcvpF1l+ZMJx31Jngf7Z1zZZW/sAkYqmGN+3ZfOEz8
KTeRR/O0kUB4Hb+tjEgtfB7AvT1GKFzH350pBEggF9ksDmMgCW007rL0lFROQrMW
cElUXhZK2SibcDeRUzasllOA7VK3QBRKeeYFTaMWwVJRtSV7QH0fsLWGJ/MwMhtT
UKQgYJ2y6wBhZzDNpAmvo1fMkphUD5oRQehoN+o7ja3s3kkbFPgE4RT57gb3lm2b
HTJmnOo8zKtf9jU3ELApwAEq3sDc+Ub09d7nD2c01e9sY0TrHvZ8nw3oKofdacVN
hYmrVfaeVXF7LtAuZ7kZMv8Zf//JF9Nq/HTii8Dy190yP8ObatbxFGbY04d4zEdV
8UYl+XvTKLGEHhHXyPEK5soUSvtK7omUd0nC7JmkerzqIR2QHm+g8p/04pFlfizI
3B7TdDOjKErUU3gWvGFap4TtRK91x3qAu77eUE3C1MBC7xEgdBP89EercPHunqRv
wAp88zCxc7jtplmyvgJelGN6tmj1L//uEnds0FAvr71vMzmSx5+J2t0v/qZHw1+B
cr/Ev0+jhobTBKOp2Wsw
=GW8w
-----END PGP SIGNATURE-----

--=-PAHwS/J5TSz6QcUXczYo--



--===============1581896830417248054==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============1581896830417248054==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung