Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.900709
Category:General
Title:Evolution Mail Client Information Disclosure Vulnerability
Summary:Evolution for Linux is prone to an information disclosure vulnerability.
Description:Summary:
Evolution for Linux is prone to an information disclosure vulnerability.

Vulnerability Insight:
The flaw is due to Mailer component in Evolution, uses world readable
permissions for the .evolution directory and some other certain directories under .evolution which causes
disclosure of sensitive information of the user's mail directories and their contents.

Vulnerability Impact:
Successful exploitation will let the local attacker gain sensitive information
about the victim's mail folders and can view their contents.

Affected Software/OS:
Evolution Mail Client version 2.26.1 and prior.

Solution:
Upgrade to Evolution Mail Client version 2.30.1 or later.

CVSS Score:
2.1

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-1631
BugTraq ID: 34921
http://www.securityfocus.com/bid/34921
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526409
http://bugzilla.gnome.org/show_bug.cgi?id=581604
http://www.openwall.com/lists/oss-security/2009/05/12/6
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.