Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 406983 (CVE-2012-1103) - <net-mail/notmuch-0.11.1-r2 : Tag Information Disclosure Vulnerability (CVE-2012-1103)
Summary: <net-mail/notmuch-0.11.1-r2 : Tag Information Disclosure Vulnerability (CVE-2...
Status: RESOLVED FIXED
Alias: CVE-2012-1103
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/48139/
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-03-05 11:26 UTC by Agostino Sarubbo
Modified: 2021-04-28 22:46 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-03-05 11:26:26 UTC
From secunia security advisory at $URL:

Description:
Certain input passed via MML tags is not properly sanitised in /emacs/notmuch-mua.el before being used. This can be exploited to attach local files to outgoing messages, if a user is tricked into replying to a message containing a specially crafted MML tag.

The vulnerability is reported in versions prior to 0.11.1.


Solution
Update to version 0.11.1.


@maintainer, ok to stabilize?
Comment 1 Amadeusz Żołnowski (RETIRED) gentoo-dev 2012-03-05 11:35:51 UTC
I have backported this fix already, please see bug #406175.
Comment 2 Agostino Sarubbo gentoo-dev 2012-03-05 11:44:56 UTC
(In reply to comment #1)
> I have backported this fix already, please see bug #406175.

OK, fixed then.

Close as ~4 noglsa because the affected version never gone stable.
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2012-09-30 20:12:40 UTC
CVE-2012-1103 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1103):
  emacs/notmuch-mua.el in Notmuch before 0.11.1, when using the Emacs
  interface, allows user-assisted remote attackers to read arbitrary files via
  crafted MML tags, which are not properly quoted in an email reply cna cause
  the files to be attached to the message.