vendor:
Kmail
by:
nnp [at] silenthack.co.uk
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Kmail
Affected Version From: 1.9.1
Affected Version To: 1.9.1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
Kmail <= 1.9.1 Crash Vulnerability
Kmail <= 1.9.1 (latest) suffers from a crash when trying to parse an incorrectly formatted <img> tag. HTML parsing must be enabled for this. This can be done by going to Settings -> Configure Kmail ->Security -> and tick Prefer HTML to Plain Text. Copy the following into your local /var/spool/mail/`whoami` or send a mail containing the HTML part to cause a crash.
Mitigation:
Disable HTML parsing in Kmail.