E-Mail:
Get our new Windows 7 eBook (PDF) for $7 with 70+ Tips. Download Now!

KDE KMail User Interface Spoofing Vulnerability

  • No Related Post

Secunia Advisory: SA14925

Critical: Less critical

Impact: Spoofing

Where: From remote

Solution Status: Unpatched

Software: KDE 3.x

Noam Rathaus has discovered a vulnerability in KMail, which can be exploited by malicious people to conduct spoofing attacks.

The vulnerability is caused due to an error where HTML code can overlay part of the user interface. This can e.g. be exploited to trick a user into believing a specially crafted mail is signed and coming from a trusted source.

Successful exploitation requires that the option “Prefer HTML to plain text” is enabled (not default setting).

The vulnerability has been confirmed in KMail 1.7.1 on KDE 3.3.1. KDE 3.3.2 is reportedly also affected. Other versions may also be affected.

Solution: Disable the “Prefer HTML to plain text” setting.”

[Continue reading KDE KMail User Interface Spoofing Vulnerability]

What Do You Think?

 
35 queries / 0.345 seconds.