============================================================================ Ubuntu Security Notice USN-1512-1 July 19, 2012 kdepim vulnerability ============================================================================ A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS - Ubuntu 11.10 Summary: KDE PIM could be made to execute JavaScript if it opened a specially crafted email. Software Description: - kdepim: Personal Information Management apps Details: It was discovered that KDE PIM html renderer incorrectly enabled JavaScript, Java and Plugins. A remote attacker could use this flaw to send an email with embedded JavaScript that possibly executes when opened. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: kdepim 4:4.8.4a-0ubuntu0.3 Ubuntu 11.10: kdepim 4:4.7.4+git111222-0ubuntu0.3 After a standard system update you need to restart your session to make all the necessary changes. References: http://www.ubuntu.com/usn/usn-1512-1 CVE-2012-3413 Package Information: https://launchpad.net/ubuntu/+source/kdepim/4:4.8.4a-0ubuntu0.3 https://launchpad.net/ubuntu/+source/kdepim/4:4.7.4+git111222-0ubuntu0.3