Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
the new package fixes the CVE-2016-7966. for more info please take a look at https://kde.org/info/security/advisory-20161006-1.txt. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-c9d15bbcbb 2016-11-03 19:08:13.237127 -------------------------------------------------------------------------------- Name : kdepimlibs Product : Fedora 24 Version : 4.14.10 Release : 15.fc24 URL : Summary : KDE PIM Libraries Description : Personal Information Management (PIM) libraries for KDE 4. -------------------------------------------------------------------------------- Update Information: the new package fixes the CVE-2016-7966. for more info please take a look at https://kde.org/info/security/advisory-20161006-1.txt -------------------------------------------------------------------------------- References: [ 1 ] Bug #1382298 - CVE-2016-7966 CVE-2016-7967 CVE-2016-7968 kdepim4: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1382298 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade kdepimlibs' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
the new package fixes the CVE-2016-7966. for more info please take a look at https://kde.org/info/security/advisory-20161006-1.txt. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-92c112a380 2016-10-31 07:34:30.242358 -------------------------------------------------------------------------------- Name : kdepimlibs Product : Fedora 25 Version : 4.14.10 Release : 15.fc25 URL : Summary : KDE PIM Libraries Description : Personal Information Management (PIM) libraries for KDE 4. -------------------------------------------------------------------------------- Update Information: the new package fixes the CVE-2016-7966. for more info please take a look at https://kde.org/info/security/advisory-20161006-1.txt -------------------------------------------------------------------------------- References: [ 1 ] Bug #1382298 - CVE-2016-7966 CVE-2016-7967 CVE-2016-7968 kdepim4: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1382298 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade kdepimlibs' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Roland Tapken discovered that insufficient input sanitising in KMail's plain text viewer allowed the injection of HTML code. For the stable distribution (jessie), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3697-1
KMail could be made to run HTML if it opened a specially crafted email.. =========================================================================Ubuntu Security Notice USN-3100-1 October 12, 2016 kdepimlibs vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: KMail could be made to run HTML if it opened a specially crafted email. Software Description: - kdepimlibs: the KDE PIM libraries Details: Roland Tapken discovered that the KDE-PIM Libraries incorrectly filtered URLs. A remote attacker could use this issue to perform an HTML injection attack in the KMail plain text viewer. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: libkpimutils4 4:4.8.5-0ubuntu0.3 After a standard system update you need to restart KMail to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3100-1 CVE-2016-7966 Package Information: https://launchpad.net/ubuntu/+source/kdepimlibs/4:4.8.5-0ubuntu0.3 . KMail may be susceptible to manipulation through specially designed emails that execute HTML injections, impacting Ubuntu 12.04 LTS along with its derivatives.. KMail Attack, HTML Injection, Ubuntu 12.04 LTS, KDE PIM Libraries, Security Update. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.