CVE-2012-1103
 
Severity Score
4.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
3
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
emacs/notmuch-mua.el in Notmuch before 0.11.1, when using the Emacs interface, allows user-assisted remote attackers to read arbitrary files via crafted MML tags, which are not properly quoted in an email reply cna cause the files to be attached to the message.
emacs/notmuch-mua.el en notmuch antes de v0.11.1, cuando se utiliza el interface Emacs, permite leer archivos de su elección a atacantes remotos con cierta ayuda de usuarios locales a través de etiquetas MML modificadas, que no están debidamente marcadas en una respuesta de correo electrónico podría ocasionar que cualquier tipo de fichero pudiera ser adjuntarse al mensaje.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2012-02-14 CVE Reserved
- 2012-09-25 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- 2024-10-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/52155 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://notmuchmail.org/news/release-0.11.1 | 2012-09-26 | |
http://secunia.com/advisories/48139 | 2012-09-26 | |
http://www.debian.org/security/2012/dsa-2416 | 2012-09-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | <= 0.11 Search vendor "Notmuchmail" for product "Notmuch" and version " <= 0.11" | - |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.1 Search vendor "Notmuchmail" for product "Notmuch" and version "0.1" | - |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.1.1 Search vendor "Notmuchmail" for product "Notmuch" and version "0.1.1" | - |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.2 Search vendor "Notmuchmail" for product "Notmuch" and version "0.2" | - |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.3 Search vendor "Notmuchmail" for product "Notmuch" and version "0.3" | - |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.3.1 Search vendor "Notmuchmail" for product "Notmuch" and version "0.3.1" | - |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.4 Search vendor "Notmuchmail" for product "Notmuch" and version "0.4" | - |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.5 Search vendor "Notmuchmail" for product "Notmuch" and version "0.5" | - |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.6 Search vendor "Notmuchmail" for product "Notmuch" and version "0.6" | - |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.6 Search vendor "Notmuchmail" for product "Notmuch" and version "0.6" | 254 |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.6 Search vendor "Notmuchmail" for product "Notmuch" and version "0.6" | rc1 |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.6.1 Search vendor "Notmuchmail" for product "Notmuch" and version "0.6.1" | - |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.7 Search vendor "Notmuchmail" for product "Notmuch" and version "0.7" | - |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.7 Search vendor "Notmuchmail" for product "Notmuch" and version "0.7" | rc1 |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.8 Search vendor "Notmuchmail" for product "Notmuch" and version "0.8" | - |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.8 Search vendor "Notmuchmail" for product "Notmuch" and version "0.8" | rc0 |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.8 Search vendor "Notmuchmail" for product "Notmuch" and version "0.8" | rc1 |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.9 Search vendor "Notmuchmail" for product "Notmuch" and version "0.9" | - |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.9 Search vendor "Notmuchmail" for product "Notmuch" and version "0.9" | rc1 |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.9 Search vendor "Notmuchmail" for product "Notmuch" and version "0.9" | rc2 |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.10 Search vendor "Notmuchmail" for product "Notmuch" and version "0.10" | - |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.10 Search vendor "Notmuchmail" for product "Notmuch" and version "0.10" | rc1 |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.10 Search vendor "Notmuchmail" for product "Notmuch" and version "0.10" | rc2 |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.10.1 Search vendor "Notmuchmail" for product "Notmuch" and version "0.10.1" | - |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.10.2 Search vendor "Notmuchmail" for product "Notmuch" and version "0.10.2" | - |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.11 Search vendor "Notmuchmail" for product "Notmuch" and version "0.11" | rc1 |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.11 Search vendor "Notmuchmail" for product "Notmuch" and version "0.11" | rc2 |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.11 Search vendor "Notmuchmail" for product "Notmuch" and version "0.11" | rc2-1 |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.11 Search vendor "Notmuchmail" for product "Notmuch" and version "0.11" | rc3 |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|
Notmuchmail Search vendor "Notmuchmail" | Notmuch Search vendor "Notmuchmail" for product "Notmuch" | 0.11 Search vendor "Notmuchmail" for product "Notmuch" and version "0.11" | rc3-1 |
Affected
| in | Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | - | - |
Safe
|