MGASA-2018-0476 - Updated messagelib packages fix security vulnerability

Publication date: 03 Dec 2018
URL: https://advisories.mageia.org/MGASA-2018-0476.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2018-19516

Some HTML emails can trick messagelib into opening a new browser window
when displaying said email as HTML. This happens even if the option to
allow the HTML emails to access remote servers is disabled in KMail
settings. This means that the owners of the servers referred in the
email can see in their access logs your IP address (CVE-2018-19516).

References:
- https://bugs.mageia.org/show_bug.cgi?id=23923
- https://kde.org/info/security/advisory-20181128-1.txt
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19516

SRPMS:
- 6/core/messagelib-17.12.2-1.1.mga6

Mageia 2018-0476: messagelib security update

Some HTML emails can trick messagelib into opening a new browser window when displaying said email as HTML

Summary

Some HTML emails can trick messagelib into opening a new browser window when displaying said email as HTML. This happens even if the option to allow the HTML emails to access remote servers is disabled in KMail settings. This means that the owners of the servers referred in the email can see in their access logs your IP address (CVE-2018-19516).

References

- https://bugs.mageia.org/show_bug.cgi?id=23923

- https://kde.org/info/security/advisory-20181128-1.txt

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19516

Resolution

MGASA-2018-0476 - Updated messagelib packages fix security vulnerability

SRPMS

- 6/core/messagelib-17.12.2-1.1.mga6

Severity
Publication date: 03 Dec 2018
URL: https://advisories.mageia.org/MGASA-2018-0476.html
Type: security
CVE: CVE-2018-19516

Related News