Описание
messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equiv="REFRESH" value.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| kf5-messagelib | fixed | 4:18.08.3-2 | package | |
| kf5-messagelib | no-dsa | stretch | package |
Примечания
https://www.kde.org/info/security/advisory-20181128-1.txt
https://github.com/KDE/messagelib/commit/34765909cdf8e55402a8567b48fb288839c61612
EPSS
Связанные уязвимости
messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equiv="REFRESH" value.
messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equiv="REFRESH" value.
messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equiv="REFRESH" value.
EPSS