Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-4166

Опубликовано: 22 июл. 2013
Источник: redhat
CVSS2: 1.2
EPSS Низкий

Описание

The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.

Отчет

Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5evolutionWill not fix
Red Hat Enterprise Linux 6cheeseFixedRHSA-2013:154020.11.2013
Red Hat Enterprise Linux 6control-centerFixedRHSA-2013:154020.11.2013
Red Hat Enterprise Linux 6ekigaFixedRHSA-2013:154020.11.2013
Red Hat Enterprise Linux 6evolutionFixedRHSA-2013:154020.11.2013
Red Hat Enterprise Linux 6evolution-data-serverFixedRHSA-2013:154020.11.2013
Red Hat Enterprise Linux 6evolution-exchangeFixedRHSA-2013:154020.11.2013
Red Hat Enterprise Linux 6evolution-mapiFixedRHSA-2013:154020.11.2013
Red Hat Enterprise Linux 6gnome-panelFixedRHSA-2013:154020.11.2013
Red Hat Enterprise Linux 6gnome-python2-desktopFixedRHSA-2013:154020.11.2013

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-697
https://bugzilla.redhat.com/show_bug.cgi?id=973728evolution: incorrect selection of recipient gpg public key for encrypted mail

EPSS

Процентиль: 76%
0.01005
Низкий

1.2 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.

CVSS3: 7.5
nvd
больше 5 лет назад

The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.

CVSS3: 7.5
debian
больше 5 лет назад

The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNO ...

CVSS3: 7.5
github
больше 3 лет назад

The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.

oracle-oval
почти 12 лет назад

ELSA-2013-1540: evolution security, bug fix, and enhancement update (LOW)

EPSS

Процентиль: 76%
0.01005
Низкий

1.2 Low

CVSS2