4.3

CVE-2012-1103

Exploit
emacs/notmuch-mua.el in Notmuch before 0.11.1, when using the Emacs interface, allows user-assisted remote attackers to read arbitrary files via crafted MML tags, which are not properly quoted in an email reply cna cause the files to be attached to the message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Notmuchmail ≫ Notmuch Version <= 0.11
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.1
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.1.1
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.2
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.3
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.3.1
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.4
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.5
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.6
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.6 Update 254
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.6 Update rc1
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.6.1
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.7
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.7 Update rc1
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.8
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.8 Update rc0
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.8 Update rc1
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.9
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.9 Update rc1
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.9 Update rc2
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.10
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.10 Update rc1
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.10 Update rc2
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.10.1
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.10.2
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.11 Update rc1
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.11 Update rc2
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.11 Update rc2-1
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.11 Update rc3
   Gnu ≫ Emacs Version -
Notmuchmail ≫ Notmuch Version 0.11 Update rc3-1
   Gnu ≫ Emacs Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.31% 0.814
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://git.notmuchmail.org/git/notmuch/blobdiff/3f2050ac221a4c940c12442f156f12fff11600c6..ae438ccd8c77831158c7c30f19710d798ee4a6b4:/emacs/notmuch-mua.el
Patch
Exploit
http://notmuchmail.org/news/release-0.11.1/
Vendor Advisory
http://secunia.com/advisories/48139
Vendor Advisory
http://www.debian.org/security/2012/dsa-2416
http://www.openwall.com/lists/oss-security/2012/03/04/5
Patch
Exploit
http://www.openwall.com/lists/oss-security/2012/03/05/6
Patch
Exploit
http://www.securityfocus.com/bid/52155