PT-2009-4116 · Gnome · Evolution
Vincent Danen
·
Published
2009-05-14
·
Updated
2009-05-23
·
CVE-2009-1631
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Evolution versions 2.26.1 and earlier
Description:
The issue concerns the Mailer component in Evolution, which uses world-readable permissions for the .evolution directory and certain directories and files under .evolution/ related to local mail. This allows local users to obtain sensitive information by reading these files.
Recommendations:
For Evolution versions 2.26.1 and earlier, consider changing the permissions of the .evolution directory and related files to restrict access and prevent unauthorized reading of sensitive information.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Evolution