Debian 10260 Published by

A kdepimlibs update has been released for Debian 7 LTS



Package : kdepimlibs
Version : 4:4.8.4-2+deb7u1
CVE ID : CVE-2016-7966
Debian Bug : 840546


Roland Tapken discovered that insufficient input sanitizing in KMail's
plain text viewer allowed attackers the injection of HTML code. This
might open the way to the exploitation of other vulnerabilities in the
HTML viewer code, which is disabled by default.

For Debian 7 "Wheezy", these problems have been fixed in version
4:4.8.4-2+deb7u1.

We recommend that you upgrade your kdepimlibs packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS