PT-2009-4116 · Gnome · Evolution

Vincent Danen

·

Published

2009-05-14

·

Updated

2009-05-23

·

CVE-2009-1631

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Evolution versions 2.26.1 and earlier
Description: The issue concerns the Mailer component in Evolution, which uses world-readable permissions for the .evolution directory and certain directories and files under .evolution/ related to local mail. This allows local users to obtain sensitive information by reading these files.
Recommendations: For Evolution versions 2.26.1 and earlier, consider changing the permissions of the .evolution directory and related files to restrict access and prevent unauthorized reading of sensitive information.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1631

Affected Products

Evolution