Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-1631
HistoryMay 14, 2009 - 12:00 a.m.

CVE-2009-1631

2009-05-1400:00:00
ubuntu.com
ubuntu.com
10

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

5.1%

The Mailer component in Evolution 2.26.1 and earlier uses world-readable
permissions for the .evolution directory, and certain directories and files
under .evolution/ related to local mail, which allows local users to obtain
sensitive information by reading these files.

Notes

Author Note
jdstrand Ubuntu 10.10 and later create the directory 0700

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

5.1%