Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-1103

Опубликовано: 25 сент. 2012
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

emacs/notmuch-mua.el in Notmuch before 0.11.1, when using the Emacs interface, allows user-assisted remote attackers to read arbitrary files via crafted MML tags, which are not properly quoted in an email reply cna cause the files to be attached to the message.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:notmuchmail:notmuch:*:*:*:*:*:*:*:*
Версия до 0.11 (включая)
cpe:2.3:a:notmuchmail:notmuch:0.1:*:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.2:*:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.3:*:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.4:*:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.5:*:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.6:*:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.6:254:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.6:rc1:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.6.1:*:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.7:*:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.7:rc1:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.8:*:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.8:rc0:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.8:rc1:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.9:*:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.9:rc1:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.9:rc2:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.10:*:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.10:rc1:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.10:rc2:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.10.1:*:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.10.2:*:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.11:rc1:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.11:rc2:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.11:rc2-1:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.11:rc3:*:*:*:*:*:*
cpe:2.3:a:notmuchmail:notmuch:0.11:rc3-1:*:*:*:*:*:*
cpe:2.3:a:gnu:emacs:-:*:*:*:*:*:*:*

EPSS

Процентиль: 71%
0.00673
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 13 лет назад

emacs/notmuch-mua.el in Notmuch before 0.11.1, when using the Emacs interface, allows user-assisted remote attackers to read arbitrary files via crafted MML tags, which are not properly quoted in an email reply cna cause the files to be attached to the message.

debian
больше 13 лет назад

emacs/notmuch-mua.el in Notmuch before 0.11.1, when using the Emacs in ...

github
больше 3 лет назад

emacs/notmuch-mua.el in Notmuch before 0.11.1, when using the Emacs interface, allows user-assisted remote attackers to read arbitrary files via crafted MML tags, which are not properly quoted in an email reply cna cause the files to be attached to the message.

EPSS

Процентиль: 71%
0.00673
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-20