Bug 1002977 (CVE-2016-7968) - VUL-0: CVE-2016-7966, CVE-2016-7967, CVE-2016-7968: kdepim4: Various JS injection attacks
Summary: VUL-0: CVE-2016-7966, CVE-2016-7967, CVE-2016-7968: kdepim4: Various JS injec...
Status: RESOLVED FIXED
Alias: CVE-2016-7968
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 42.1
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Wolfgang Rosenauer
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/173158/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-10-05 07:40 UTC by Johannes Segitz
Modified: 2018-02-16 12:50 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2016-10-05 07:40:20 UTC
CVE-2016-7966: HTML injection in plain text viewer
CVE-2016-7967: JavaScript access to local and remote URLs
CVE-2016-7968: JavaScript execution in HTML Mails

Unfortunately the fixes were not listed directly

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-7966
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-7967
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-7968
http://seclists.org/oss-sec/2016/q4/23
Comment 1 Swamp Workflow Management 2016-10-05 22:00:14 UTC
bugbot adjusting priority
Comment 2 Andreas Stieger 2016-10-07 07:55:22 UTC
https://build.opensuse.org/request/show/433715

  maintenance_incident: home:sumski:branches:openSUSE:Leap:42.1:Update/kcoreaddons@9f91a969d9ac6bc7fbc3f11f2a94daf0 -> openSUSE:Maintenance (release in openSUSE:Leap:42.1:Update)
Comment 3 Andreas Stieger 2016-10-07 08:04:12 UTC
Hrvoje, i have a couple of questions regarding your submission for 42.1 maintenance:

This issue not seem to be fixed in openSUSE:Factory or KDE:Frameworks5/kcoreaddons. Could you submit there first or confirm that it is fixed there already?

Also fixes for CVE-2016-7967, CVE-2016-7968 do not seem to be included. Could you add these?

Your submission adds:
0001-Fix-very-old-bug-when-we-remove-space-in-url-as-foo-.patch
0002-Don-t-convert-as-url-an-url-which-has-a.patch (CVE-2016-7966)
Is the first patch unrelated?

Finally, I actually show this package as being maintained in the distros below:
openSUSE:13.2:Update/kcoreaddons
openSUSE:Backports:SLE-12-SP1/kcoreaddons
openSUSE:Leap:42.1:Update/kcoreaddons
Would you be able to submit for all?
Comment 4 Forgotten User DV81ZEWZkN 2016-10-07 08:24:37 UTC
(In reply to Andreas Stieger from comment #3)
> Hrvoje, i have a couple of questions regarding your submission for 42.1
> maintenance:
> 
> This issue not seem to be fixed in openSUSE:Factory or
> KDE:Frameworks5/kcoreaddons. Could you submit there first or confirm that it
> is fixed there already?

5.27.0 which contains the fix is in KDE:Frameworks5, and i've submitted 5.26.0 + patch to Factory.

> 
> Also fixes for CVE-2016-7967, CVE-2016-7968 do not seem to be included.
> Could you add these?
Sure, but these are for different packages.
 
> Your submission adds:
> 0001-Fix-very-old-bug-when-we-remove-space-in-url-as-foo-.patch
> 0002-Don-t-convert-as-url-an-url-which-has-a.patch (CVE-2016-7966)
> Is the first patch unrelated?
> 
> Finally, I actually show this package as being maintained in the distros
> below:
> openSUSE:13.2:Update/kcoreaddons
> openSUSE:Backports:SLE-12-SP1/kcoreaddons
> openSUSE:Leap:42.1:Update/kcoreaddons
> Would you be able to submit for all?

Yes. Except i don't know the procedure for SLE.
Comment 5 Andreas Stieger 2016-10-07 08:57:26 UTC
Any one of the following will make maintenance branches:

osc mbranch kcoreaddons
osc branch -M openSUSE:Backports:SLE-12-SP1/kcoreaddons

Let me know if you need help with that.
Comment 6 Andreas Stieger 2016-10-10 14:16:09 UTC
I fixed up the 42.1 and openSUSE:Backports:SLE-12-SP1 submissions:
https://build.opensuse.org/request/show/434123
https://build.opensuse.org/request/show/434122

Any chance you could submit for 13.2 if it is affected?
Comment 7 Bernhard Wiedemann 2016-10-10 16:00:31 UTC
This is an autogenerated message for OBS integration:
This bug (1002977) was mentioned in
https://build.opensuse.org/request/show/434138 13.2 / kcoreaddons
Comment 8 Swamp Workflow Management 2016-10-18 12:10:04 UTC
openSUSE-SU-2016:2558-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1002977
CVE References: CVE-2016-7966
Sources used:
openSUSE Leap 42.1 (src):    kcoreaddons-5.21.0-18.1
openSUSE 13.2 (src):    kcoreaddons-5.11.0-27.1
Comment 9 Swamp Workflow Management 2016-10-18 12:10:18 UTC
openSUSE-SU-2016:2559-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1002977
CVE References: CVE-2016-7966
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    kcoreaddons-5.20.0-6.1
Comment 10 Andreas Stieger 2018-02-16 12:50:21 UTC
all done, rest is EOL