PT-2013-1408 · Gnome+3 · Gnome Evolution+3
Matt Mccutchen
·
Publicado
2013-02-20
·
Atualizado
2023-02-13
·
CVE-2011-3201
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GNOME Evolution versions prior to 3.2.3
Description
The issue allows user-assisted remote attackers to read arbitrary files via the
attachment parameter to a "mailto:" URL, which attaches the file to the email. This enables attackers to access files on the user's system by manipulating the attachment parameter in a mailto URL.Recommendations
For versions prior to 3.2.3, update to version 3.2.3 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the
attachment parameter in mailto URLs until the update is applied.Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Debian
Gnome Evolution
Red Hat