KMail Client Denial Of Service Vulnerability
BID:4177
Info
KMail Client Denial Of Service Vulnerability
| Bugtraq ID: | 4177 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-0342 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Discovery of this issue is credited to Andrey Kazakov <[email protected]>. |
| Vulnerable: |
KDE kmail 1.2 |
| Not Vulnerable: |
KDE kmail 1.3.1 |
Discussion
KMail Client Denial Of Service Vulnerability
KMail is a graphical mail client for KDE (K Desktop Environment). KDE is a graphical desktop environment for Linux and Unix variants.
It has been reported that KMail crashes when it attempts to open an e-mail with a message body that is approximately 55kb in length.
A remote attacker may potentially exploit this issue to cause a denial of service to a user of the e-mail client.
This issue has been reported for KMail 1.2 running under KDE 2.1.1. Other versions and environments may be affected by this vulnerability. This issue does not appear to affect KMail 1.3.1 running under KDE 2.2.
KMail is a graphical mail client for KDE (K Desktop Environment). KDE is a graphical desktop environment for Linux and Unix variants.
It has been reported that KMail crashes when it attempts to open an e-mail with a message body that is approximately 55kb in length.
A remote attacker may potentially exploit this issue to cause a denial of service to a user of the e-mail client.
This issue has been reported for KMail 1.2 running under KDE 2.1.1. Other versions and environments may be affected by this vulnerability. This issue does not appear to affect KMail 1.3.1 running under KDE 2.2.
Exploit / POC
KMail Client Denial Of Service Vulnerability
This issue can reportedly be reproduced by sending an e-mail with a message body that is approximately 55kb in length. When the KMail client attempts to open such an e-mail, it allegedly crashes.
This issue can reportedly be reproduced by sending an e-mail with a message body that is approximately 55kb in length. When the KMail client attempts to open such an e-mail, it allegedly crashes.