LWN.net Logo

notmuch: information disclosure

Package(s):notmuch CVE #(s):CVE-2011-1103
Created:February 23, 2012 Updated:March 19, 2012
Description:

From the Debian advisory:

It was discovered that Notmuch, an email indexer, did not sufficiently escape Emacs MML tags. When using the Emacs interface, a user could be tricked into replying to a maliciously formatted message which could lead to files from the local machine being attached to the outgoing message.

Alerts:
Debian DSA-2416-1 2012-02-23
Fedora FEDORA-2012-3312 2012-03-17
Fedora FEDORA-2012-3315 2012-03-17

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds