KMail HTML Element Handling Denial Of Service Vulnerability
BID:20539
Info
KMail HTML Element Handling Denial Of Service Vulnerability
| Bugtraq ID: | 20539 |
| Class: | Design Error |
| CVE: |
CVE-2006-7139 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2006 12:00AM |
| Updated: | Mar 19 2015 09:10AM |
| Credit: | nnp <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server SDK 9 SuSE SUSE Linux Enterprise Server 9 SP3 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10 SuSE Linux Professional 10.2 x86_64 SuSE Linux Personal 10.2 x86_64 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. SUSE CORE 9 for x86 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Office Server S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Openexchange Server S.u.S.E. Linux Office Server S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Desktop 1.0 S.u.S.E. Linux Desktop 10 S.u.S.E. Linux Database Server 0 S.u.S.E. Linux Connectivity Server S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc KDE kmail 1.102 KDE kmail 1.101 KDE kmail 1.100 KDE kmail 1.89 KDE kmail 1.88 KDE kmail 1.87 KDE kmail 1.86.2 36 KDE kmail 1.9.1 KDE kmail 1.7.1 KDE kmail 1.3.1 KDE kmail 1.2 KDE kmail 1.0.29 .2 KDE kmail 1.0.29 .1 KDE kmail 1.0.29 KDE kmail 1.0.28 KDE kmail 1.0.27 KDE kmail 1.0.26 KDE kmail 1.0.25 KDE kmail 1.0.24 KDE kmail 0.0.29 2 |
| Not Vulnerable: | |
Discussion
KMail HTML Element Handling Denial Of Service Vulnerability
KMail is prone to an unspecified denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
KMail 1.9.1 and prior versions are vulnerable to this issue.
KMail is prone to an unspecified denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
KMail 1.9.1 and prior versions are vulnerable to this issue.
Exploit / POC
KMail HTML Element Handling Denial Of Service Vulnerability
An attacker may trigger this issue by constructing a malicious email message and sending it to an unsuspecting victim using the vulnerable application.
The following message demonstrates this issue:
An attacker may trigger this issue by constructing a malicious email message and sending it to an unsuspecting victim using the vulnerable application.
The following message demonstrates this issue:
Solution / Fix
KMail HTML Element Handling Denial Of Service Vulnerability
Solution:
Please see the references for further information.
Solution:
Please see the references for further information.
References
KMail HTML Element Handling Denial Of Service Vulnerability
References:
References:
- KMail Home Page (KMail)
- Kmail <= 1.9.1 (table/frameset) DOS (nnp
)