LWN.net Logo

evolution: information disclosure

Package(s):evolution CVE #(s):CVE-2011-3201
Created:February 21, 2013 Updated:March 11, 2013
Description: From the Red Hat advisory:

The way Evolution handled mailto URLs allowed any file to be attached to the new message. This could lead to information disclosure if the user did not notice the attached file before sending the message. With this update, mailto URLs cannot be used to attach certain files, such as hidden files or files in hidden directories, files in the /etc/ directory, or files specified using a path containing "..".

Alerts:
Red Hat RHSA-2013:0516-02 2013-02-21
Oracle ELSA-2013-0516 2013-02-25
Scientific Linux SL-evol-20130304 2013-03-04
CentOS CESA-2013:0516 2013-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds