[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2416-1 notmuch -- information disclosure

ID: oval:org.secpod.oval:def:600739Date: (C)2012-03-02   (M)2022-10-10
Class: PATCHFamily: unix




It was discovered that Notmuch, an email indexer, did not sufficiently escape Emacs MML tags. When using the Emacs interface, a user could be tricked into replying to a maliciously formatted message which could lead to files from the local machine being attached to the outgoing message.

Platform:
Debian 6.0
Product:
notmuch
Reference:
DSA-2416-1
CVE-2012-1103
CVE    1
CVE-2012-1103
CPE    2
cpe:/o:debian:debian_linux:6.x
cpe:/a:notmuchmail:notmuch

© SecPod Technologies