CVE-2011-3201

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
08/03/2013
Last modified:
11/04/2025

Description

GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:oracle:solaris:11.2:*:*:*:*:*:*:*
cpe:2.3:a:gnome:evolution:*:*:*:*:*:*:*:* 3.0.3 (including)
cpe:2.3:a:gnome:evolution:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:gnome:evolution:1.2:*:*:*:*:*:*:*
cpe:2.3:a:gnome:evolution:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:gnome:evolution:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:gnome:evolution:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:gnome:evolution:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:gnome:evolution:1.4:*:*:*:*:*:*:*
cpe:2.3:a:gnome:evolution:1.4.3:*:*:*:*:*:*:*
cpe:2.3:a:gnome:evolution:1.4.4:*:*:*:*:*:*:*
cpe:2.3:a:gnome:evolution:1.4.5:*:*:*:*:*:*:*
cpe:2.3:a:gnome:evolution:1.4.6:*:*:*:*:*:*:*
cpe:2.3:a:gnome:evolution:1.5:*:*:*:*:*:*:*
cpe:2.3:a:gnome:evolution:1.11:*:*:*:*:*:*:*