Improper Input Validation in KDE Applications by KDE
CVE-2018-19516
5.3MEDIUM
What is CVE-2018-19516?
The vulnerability arises from inadequate handling of the http-equiv="REFRESH" value in the defaultrenderer.cpp file of messagepartthemes within messagelib. This flaw can potentially allow malicious actors to manipulate the behavior of the application, leading to unexpected redirects or the execution of arbitrary content. Users of affected KDE Applications should ensure they are running version 18.12.0 or later to mitigate these risks.
