CVE-2011-3201
Publication date 8 March 2013
Last updated 24 July 2024
Ubuntu priority
GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.
Status
Package | Ubuntu Release | Status |
---|---|---|
evolution | 16.04 LTS xenial |
Not affected
|
14.04 LTS trusty | Not in release | |
Notes
jdstrand
no upstream patch yet (2011-10-13). In discussion in RedHat bug. requires user to not notice the attachment