PT-2013-1408 · Gnome+3 · Gnome Evolution+3
Matt Mccutchen
·
Published
2013-02-20
·
Updated
2023-02-13
·
CVE-2011-3201
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GNOME Evolution versions prior to 3.2.3
Description
The issue allows user-assisted remote attackers to read arbitrary files via the
attachment parameter to a "mailto:" URL, which attaches the file to the email. This enables attackers to access files on the user's system by manipulating the attachment parameter in a mailto URL.Recommendations
For versions prior to 3.2.3, update to version 3.2.3 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the
attachment parameter in mailto URLs until the update is applied.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Debian
Gnome Evolution
Red Hat