First published: Fri May 01 2009(Updated: )
A Debian bug report [1] brought to light the fact that Evolution does not create its data files with appropriate permissions. Because of this, if user A on a system uses Evolut ion for email, user B can read any of user A's email. The default permissions for ~/.evolution is 0755, and the default permissions for Evolution data files is 0644 (although s trangely enough the default permissions for .index* files is 0600). As well, by default in Fedora and RHEL5, a user's home directory has mode 0755 permissions. By contrast, Firefox creates ~/.mozilla/firefox as mode 0700, protecting user bookmarks and caches. Evolution should probably create/enforce ~/.evolution being mode 0700. [1] <a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526409">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526409</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME Evolution | =2.4 | |
GNOME Evolution | =2.0.1 | |
GNOME Evolution | =1.2.4 | |
GNOME Evolution | =1.4.5 | |
GNOME Evolution | =1.4.6 | |
GNOME Evolution | =2.0.2 | |
GNOME Evolution | <=2.26.1 | |
GNOME Evolution | =1.4.4 | |
GNOME Evolution | =1.2.1 | |
GNOME Evolution | =2.6 | |
GNOME Evolution | =1.0.8 | |
GNOME Evolution | =2.12 | |
GNOME Evolution | =1.4.3 | |
GNOME Evolution | =1.2.2 | |
GNOME Evolution | =2.24 | |
GNOME Evolution | =1.4 | |
GNOME Evolution | =2.0.0 | |
GNOME Evolution | =1.2 | |
GNOME Evolution | =1.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1631 has a medium severity rating as it potentially allows unauthorized access to users' email data.
To fix CVE-2009-1631, you need to change the permissions of the ~/.evolution directory to restrict access.
CVE-2009-1631 affects all versions of GNOME Evolution up to and including version 2.26.1.
The nature of the vulnerability in CVE-2009-1631 is improper file permissions allowing one user to read another user's email.
Yes, patches are available in later versions of GNOME Evolution which correct the permission settings.