CVE-2012-1103: Input Validation
Published Sep 25, 2012
·Updated
emacs/notmuch-mua.el in Notmuch before 0.11.1, when using the Emacs interface, allows user-assisted remote attackers to read arbitrary files via crafted MML tags, which are not properly quoted in an email reply cna cause the files to be attached to the message.
Affected Software
31 affected components
Notmuchmail Notmuch<=0.11
Notmuchmail Notmuch=0.1
Notmuchmail Notmuch=0.1.1
Notmuchmail Notmuch=0.2
Notmuchmail Notmuch=0.3
Notmuchmail Notmuch=0.3.1
Notmuchmail Notmuch=0.4
Notmuchmail Notmuch=0.5
Notmuchmail Notmuch=0.6
Notmuchmail Notmuch=0.6-254
Notmuchmail Notmuch=0.6-rc1
Notmuchmail Notmuch=0.6.1
Notmuchmail Notmuch=0.7
Notmuchmail Notmuch=0.7-rc1
Notmuchmail Notmuch=0.8
Notmuchmail Notmuch=0.8-rc0
Notmuchmail Notmuch=0.8-rc1
Notmuchmail Notmuch=0.9
Notmuchmail Notmuch=0.9-rc1
Notmuchmail Notmuch=0.9-rc2
Notmuchmail Notmuch=0.10
Notmuchmail Notmuch=0.10-rc1
Notmuchmail Notmuch=0.10-rc2
Notmuchmail Notmuch=0.10.1
Notmuchmail Notmuch=0.10.2
Notmuchmail Notmuch=0.11-rc1
Notmuchmail Notmuch=0.11-rc2
Notmuchmail Notmuch=0.11-rc2-1
Notmuchmail Notmuch=0.11-rc3
Notmuchmail Notmuch=0.11-rc3-1
GNU Emacs
Remediation
Patch Available
Patch Available
Event History
Sep 25, 2012
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1103?
CVE-2012-1103 has a moderate severity as it allows user-assisted remote attackers to read arbitrary files.
2
How do I fix CVE-2012-1103?
To fix CVE-2012-1103, upgrade Notmuch to version 0.11.1 or later.
3
Which versions of Notmuch are affected by CVE-2012-1103?
CVE-2012-1103 affects Notmuch versions prior to 0.11.1.
4
How does CVE-2012-1103 work?
CVE-2012-1103 exploits crafted MML tags that can cause arbitrary files to be attached in email replies.
5
Should I be concerned about CVE-2012-1103 if I use Notmuch?
Yes, if you use an affected version of Notmuch, you should upgrade to avoid potential data exposure.