CVE-2012-1103
Last modified
CVE-2012-1103 is a vulnerability of currently unknown severity. emacs/notmuch-mua.el in Notmuch before 0.11.1, when using the Emacs interface, allows user-assisted remote attackers to read arbitrary files via crafted MML tags, which are not properly quoted in an email reply cna cause the files to be attached to the message.. EPSS estimates a 2.32% chance of exploitation in the next 30 days.
Description
emacs/notmuch-mua.el in Notmuch before 0.11.1, when using the Emacs interface, allows user-assisted remote attackers to read arbitrary files via crafted MML tags, which are not properly quoted in an email reply cna cause the files to be attached to the message.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Notmuchmail | Notmuch | <= 0.11 | — |
| Notmuchmail | Notmuch | 0.1 | — |
| Notmuchmail | Notmuch | 0.1.1 | — |
| Notmuchmail | Notmuch | 0.2 | — |
| Notmuchmail | Notmuch | 0.3 | — |
| Notmuchmail | Notmuch | 0.3.1 | — |
| Notmuchmail | Notmuch | 0.4 | — |
| Notmuchmail | Notmuch | 0.5 | — |
| Notmuchmail | Notmuch | 0.6 | — |
| Notmuchmail | Notmuch | 0.6.1 | — |
| Notmuchmail | Notmuch | 0.7 | — |
| Notmuchmail | Notmuch | 0.8 | — |
| Notmuchmail | Notmuch | 0.9 | — |
| Notmuchmail | Notmuch | 0.10 | — |
| Notmuchmail | Notmuch | 0.10.1 | — |
| Notmuchmail | Notmuch | 0.10.2 | — |
| Notmuchmail | Notmuch | 0.11 | Rc1 |
References
- http://notmuchmail.org/news/release-0.11.1/Vendor Advisory
- http://secunia.com/advisories/48139Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/03/04/5Exploit, Patch
- http://www.openwall.com/lists/oss-security/2012/03/05/6Exploit, Patch
- http://notmuchmail.org/news/release-0.11.1/Vendor Advisory
- http://secunia.com/advisories/48139Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/03/04/5Exploit, Patch
- http://www.openwall.com/lists/oss-security/2012/03/05/6Exploit, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-1103?
How severe is CVE-2012-1103?
How do I fix CVE-2012-1103?
Are you affected by CVE-2012-1103?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
