Lucene search

K
cveMitreCVE-2009-1631
HistoryMay 14, 2009 - 5:30 p.m.

CVE-2009-1631

2009-05-1417:30:00
CWE-264
mitre
web.nvd.nist.gov
29
cve-2009-1631
evolution
mailer component
vulnerability
sensitive information
nvd

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

5.9

Confidence

Low

EPSS

0

Percentile

5.1%

The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to local mail, which allows local users to obtain sensitive information by reading these files.

Affected configurations

Nvd
Node
gnomeevolutionRange2.26.1
OR
gnomeevolutionMatch1.0.8
OR
gnomeevolutionMatch1.2
OR
gnomeevolutionMatch1.2.1
OR
gnomeevolutionMatch1.2.2
OR
gnomeevolutionMatch1.2.3
OR
gnomeevolutionMatch1.2.4
OR
gnomeevolutionMatch1.4
OR
gnomeevolutionMatch1.4.3
OR
gnomeevolutionMatch1.4.4
OR
gnomeevolutionMatch1.4.5
OR
gnomeevolutionMatch1.4.6
OR
gnomeevolutionMatch2.0.0
OR
gnomeevolutionMatch2.0.1
OR
gnomeevolutionMatch2.0.2
OR
gnomeevolutionMatch2.4
OR
gnomeevolutionMatch2.6
OR
gnomeevolutionMatch2.12
OR
gnomeevolutionMatch2.24
VendorProductVersionCPE
gnomeevolution*cpe:2.3:a:gnome:evolution:*:*:*:*:*:*:*:*
gnomeevolution1.0.8cpe:2.3:a:gnome:evolution:1.0.8:*:*:*:*:*:*:*
gnomeevolution1.2cpe:2.3:a:gnome:evolution:1.2:*:*:*:*:*:*:*
gnomeevolution1.2.1cpe:2.3:a:gnome:evolution:1.2.1:*:*:*:*:*:*:*
gnomeevolution1.2.2cpe:2.3:a:gnome:evolution:1.2.2:*:*:*:*:*:*:*
gnomeevolution1.2.3cpe:2.3:a:gnome:evolution:1.2.3:*:*:*:*:*:*:*
gnomeevolution1.2.4cpe:2.3:a:gnome:evolution:1.2.4:*:*:*:*:*:*:*
gnomeevolution1.4cpe:2.3:a:gnome:evolution:1.4:*:*:*:*:*:*:*
gnomeevolution1.4.3cpe:2.3:a:gnome:evolution:1.4.3:*:*:*:*:*:*:*
gnomeevolution1.4.4cpe:2.3:a:gnome:evolution:1.4.4:*:*:*:*:*:*:*
Rows per page:
1-10 of 191

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

5.9

Confidence

Low

EPSS

0

Percentile

5.1%