Some HTML emails can trick messagelib into opening a new browser window when displaying said email as HTML. This happens even if the option to allow the HTML emails to access remote servers is disabled in KMail settings. This means that the owners of the servers referred in the email can see in their access logs your IP address (CVE-2018-19516). . MGASA-2018-0476 - Updated messagelib packages fix security vulnerability Publication date: 03 Dec 2018 URL: https://advisories.mageia.org/MGASA-2018-0476.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-19516 Some HTML emails can trick messagelib into opening a new browser window when displaying said email as HTML. This happens even if the option to allow the HTML emails to access remote servers is disabled in KMail settings. This means that the owners of the servers referred in the email can see in their access logs your IP address (CVE-2018-19516). References: - https://bugs.mageia.org/show_bug.cgi?id=23923 - https://kde.org/info/security/advisory-20181128-1.txt - https://www.cve.org/CVERecord?id=CVE-2018-19516 SRPMS: - 6/core/messagelib-17.12.2-1.1.mga6 . The latest messagelib updates fix vulnerabilities related to HTML email processing and enhance the protection of user IP information.. messagelib security, Mageia update, HTML email threat. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.