CVE-2011-3201
evolution: mailto URL scheme attachment header improper input validation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.
GNOME Evolution antes de v3.2.3 permite leer archivos de su elección a atacantes remotos con la yuda del usuario local a través del parámetro 'attachment' a una URL mailto: , que adjunta el archivo al correo electrónico.
Evolution is the GNOME mailer, calendar, contact manager and communication tool. The components which make up Evolution are tightly integrated with one another and act as a seamless personal information-management tool. The way Evolution handled mailto URLs allowed any file to be attached to the new message. This could lead to information disclosure if the user did not notice the attached file before sending the message. With this update, mailto URLs cannot be used to attach certain files, such as hidden files or files in hidden directories, files in the /etc/ directory, or files specified using a path containing "..".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-08-19 CVE Reserved
- 2013-02-21 CVE Published
- 2024-08-06 CVE Updated
- 2025-07-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-356: Product UI does not Warn User of Unsafe Actions
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html | Third Party Advisory |
|
https://bugzilla.gnome.org/show_bug.cgi?id=657374 | Issue Tracking | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/82450 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2013-0516.html | 2023-02-13 | |
https://access.redhat.com/security/cve/CVE-2011-3201 | 2013-02-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Solaris Search vendor "Oracle" for product "Solaris" | 11.2 Search vendor "Oracle" for product "Solaris" and version "11.2" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | <= 3.0.3 Search vendor "Gnome" for product "Evolution" and version " <= 3.0.3" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 1.0.8 Search vendor "Gnome" for product "Evolution" and version "1.0.8" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 1.2 Search vendor "Gnome" for product "Evolution" and version "1.2" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 1.2.1 Search vendor "Gnome" for product "Evolution" and version "1.2.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 1.2.2 Search vendor "Gnome" for product "Evolution" and version "1.2.2" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 1.2.3 Search vendor "Gnome" for product "Evolution" and version "1.2.3" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 1.2.4 Search vendor "Gnome" for product "Evolution" and version "1.2.4" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 1.4 Search vendor "Gnome" for product "Evolution" and version "1.4" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 1.4.3 Search vendor "Gnome" for product "Evolution" and version "1.4.3" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 1.4.4 Search vendor "Gnome" for product "Evolution" and version "1.4.4" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 1.4.5 Search vendor "Gnome" for product "Evolution" and version "1.4.5" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 1.4.6 Search vendor "Gnome" for product "Evolution" and version "1.4.6" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 1.5 Search vendor "Gnome" for product "Evolution" and version "1.5" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 1.11 Search vendor "Gnome" for product "Evolution" and version "1.11" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.0 Search vendor "Gnome" for product "Evolution" and version "2.0" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.0.0 Search vendor "Gnome" for product "Evolution" and version "2.0.0" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.0.1 Search vendor "Gnome" for product "Evolution" and version "2.0.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.0.2 Search vendor "Gnome" for product "Evolution" and version "2.0.2" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.1 Search vendor "Gnome" for product "Evolution" and version "2.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.2 Search vendor "Gnome" for product "Evolution" and version "2.2" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.2.1 Search vendor "Gnome" for product "Evolution" and version "2.2.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.3.1 Search vendor "Gnome" for product "Evolution" and version "2.3.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.3.2 Search vendor "Gnome" for product "Evolution" and version "2.3.2" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.3.3 Search vendor "Gnome" for product "Evolution" and version "2.3.3" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.3.4 Search vendor "Gnome" for product "Evolution" and version "2.3.4" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.3.5 Search vendor "Gnome" for product "Evolution" and version "2.3.5" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.3.6 Search vendor "Gnome" for product "Evolution" and version "2.3.6" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.3.6.1 Search vendor "Gnome" for product "Evolution" and version "2.3.6.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.3.7 Search vendor "Gnome" for product "Evolution" and version "2.3.7" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.4 Search vendor "Gnome" for product "Evolution" and version "2.4" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.4.2.1 Search vendor "Gnome" for product "Evolution" and version "2.4.2.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.6 Search vendor "Gnome" for product "Evolution" and version "2.6" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.8.1 Search vendor "Gnome" for product "Evolution" and version "2.8.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.10.3 Search vendor "Gnome" for product "Evolution" and version "2.10.3" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.12 Search vendor "Gnome" for product "Evolution" and version "2.12" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.12.3 Search vendor "Gnome" for product "Evolution" and version "2.12.3" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.22.1 Search vendor "Gnome" for product "Evolution" and version "2.22.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.22.3 Search vendor "Gnome" for product "Evolution" and version "2.22.3" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.24 Search vendor "Gnome" for product "Evolution" and version "2.24" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.24.5 Search vendor "Gnome" for product "Evolution" and version "2.24.5" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.26.1 Search vendor "Gnome" for product "Evolution" and version "2.26.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.26.3 Search vendor "Gnome" for product "Evolution" and version "2.26.3" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.28.3.1 Search vendor "Gnome" for product "Evolution" and version "2.28.3.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.30.3 Search vendor "Gnome" for product "Evolution" and version "2.30.3" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Evolution Search vendor "Gnome" for product "Evolution" | 2.32.3 Search vendor "Gnome" for product "Evolution" and version "2.32.3" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Search vendor "Redhat" for product "Enterprise Linux Server" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Server" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Workstation Search vendor "Redhat" for product "Enterprise Linux Workstation" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Workstation" and version "6.0" | - |
Affected
|