CVE-2011-3201: Infoleak

Published Aug 25, 2011
·
Updated

GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.

Other sources

This is another Evolution security issue that I found upstream but presume also affects Fedora and would like to put on the Fedora security team's radar. If my filing such bugs is not appreciated, please let me know and I will stop.

Description of problem: Evolution registers a "mailto:" URL handler that accepts a parameter to attach a local file. Thus, a web site can launch the composer on an email with a confidential file attached and try to trick the user into sending it.

Version-Release number of selected component (if applicable): Upstream gnome-3-0 branch as of 2011-08-24

How reproducible: Always

Steps to Reproduce: 1. Go to https://mattmccutchen.net/private/evolution-mailto-test . 2. Click "Send" in the composer.

Actual results: Your SSH private key is emailed to me.

Expected results: A prompt is shown and you decline to attach the private key.

Red Hat

Affected Software

49 affected components
Oracle Solaris=11.2
Gnome Evolution<=3.0.3
Gnome Evolution=1.0.8
Gnome Evolution=1.2
Gnome Evolution=1.2.1
Gnome Evolution=1.2.2
Gnome Evolution=1.2.3
Gnome Evolution=1.2.4
Gnome Evolution=1.4
Gnome Evolution=1.4.3
Gnome Evolution=1.4.4
Gnome Evolution=1.4.5
Gnome Evolution=1.4.6
Gnome Evolution=1.5
Gnome Evolution=1.11
Gnome Evolution=2.0
Gnome Evolution=2.0.0
Gnome Evolution=2.0.1
Gnome Evolution=2.0.2
Gnome Evolution=2.1
Gnome Evolution=2.2
Gnome Evolution=2.2.1
Gnome Evolution=2.3.1
Gnome Evolution=2.3.2
Gnome Evolution=2.3.3
Gnome Evolution=2.3.4
Gnome Evolution=2.3.5
Gnome Evolution=2.3.6
Gnome Evolution=2.3.6.1
Gnome Evolution=2.3.7
Gnome Evolution=2.4
Gnome Evolution=2.4.2.1
Gnome Evolution=2.6
Gnome Evolution=2.8.1
Gnome Evolution=2.10.3
Gnome Evolution=2.12
Gnome Evolution=2.12.3
Gnome Evolution=2.22.1
Gnome Evolution=2.22.3
Gnome Evolution=2.24
Gnome Evolution=2.24.5
Gnome Evolution=2.26.1
Gnome Evolution=2.26.3
Gnome Evolution=2.28.3.1
Gnome Evolution=2.30.3
Gnome Evolution=2.32.3
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Workstation=6.0

Event History

Aug 25, 2011
Data Sourced
08:10 PM
DescriptionSeverityAffected Software
Mar 8, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2011-3201?

CVE-2011-3201 is considered to be of medium severity due to its potential to allow unauthorized access to arbitrary files.

2

How do I fix CVE-2011-3201?

The recommended fix for CVE-2011-3201 is to upgrade to GNOME Evolution version 3.2.3 or later.

3

Which versions of GNOME Evolution are affected by CVE-2011-3201?

CVE-2011-3201 affects multiple versions of GNOME Evolution prior to 3.2.3.

4

Can CVE-2011-3201 be exploited without user interaction?

Exploitation of CVE-2011-3201 requires user interaction to trigger the file reading via a mailto: URL.

5

What platforms are affected by CVE-2011-3201?

CVE-2011-3201 affects GNOME Evolution on various platforms, including Oracle Solaris and Red Hat Enterprise Linux.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203