20061014 Kmail <= 1.9.1 (table/frameset) DOSmailing list
http://archives.neohapsis.com/archives/fulldisclosure/2006-10/0293.html CVE-2006-7139
KMail 1.x - HTML Element Handling Denial of Service
Record summary
CVE-2006-7139 has a selected CVSS score of 2.6; EIP currently links 1 catalogued exploit.
Description
Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, allows remote attackers to cause a denial of service (crash) via an HTML e-mail with certain table and frameset tags that trigger a segmentation fault, possibly involving invalid free or delete operations.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBKMail 1.x - HTML Element Handling Denial of ServiceExploitDB exploitby nnpNot analyzed1 file
References
924889Third-party advisory
http://secunia.com/advisories/24889 2347Third-party advisory
http://securityreason.com/securityalert/2347 SUSE-SR:2007:006Vendor advisory
http://www.novell.com/linux/security/advisories/2007_6_sr.html 20061015 Re: [Full-disclosure] Kmail <= 1.9.1 (table/frameset) DOSmailing list
http://www.securityfocus.com/archive/1/448766/100/0/threaded 20061014 Kmail <= 1.9.1 (table/frameset) DOSmailing list
http://www.securityfocus.com/archive/1/448768/100/0/threaded 20539vdb entry
http://www.securityfocus.com/bid/20539 kmail-table-frameset-dos(29557)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/29557 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-7139