GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade evolution-conduitsUpgrade evolution-helpUpgrade evolution-pstUpgrade evolution-perlUpgrade evolutionUpgrade evolution-develUpgrade evolution-spamassassin | Dec 1, 2016 | Mar 8, 2013 |
| Debian | — | No solution exists | May 15, 2025 | May 15, 2025 |
| Oracle Solaris | — | Upgrade mail/evolution to version 2.30.3-0.175.2.8.0.4.0 on Solaris 11.2Upgrade mail/evolution/connector/evolution-exchange to version 2.30.3-0.175.2.8.0.4.0 on Solaris 11.2 | May 29, 2017 | Mar 8, 2013 |
| Oracle_linux | — | Upgrade evolution-conduitsUpgrade evolutionUpgrade evolution-develUpgrade evolution-spamassassinUpgrade evolution-pstUpgrade evolution-perlUpgrade evolution-help | Oct 16, 2024 | Mar 8, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 25, 2011 |
| Suse | — | Upgrade evolution-data-server-x86Upgrade evolution-ews-langUpgrade evolution-langUpgrade evolution-ewsUpgrade evolution-pilotUpgrade evolution-data-server-langUpgrade evolution-data-server-32bitUpgrade evolution-data-serverUpgrade evolution-develUpgrade evolution-data-server-develUpgrade evolution | Dec 12, 2013 | Jul 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub