Vulnerability Description
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Evolution | <= 3.8.4 |
| Gnome | Evolution Data Server | <= 3.9.5 |
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Workstation | 6.0 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2013-1540.htmlThird Party Advisory
- http://seclists.org/oss-sec/2013/q3/191Mailing ListThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=973728Issue TrackingThird Party Advisory
- https://git.gnome.org/browse/evolution-data-server/commit/?h=gnome-3-8&id=f7059bPatchVendor Advisory
- https://git.gnome.org/browse/evolution-data-server/commit/?id=5d8b92c622f6927b25PatchVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1540.htmlThird Party Advisory
- http://seclists.org/oss-sec/2013/q3/191Mailing ListThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=973728Issue TrackingThird Party Advisory
- https://git.gnome.org/browse/evolution-data-server/commit/?h=gnome-3-8&id=f7059bPatchVendor Advisory
- https://git.gnome.org/browse/evolution-data-server/commit/?id=5d8b92c622f6927b25PatchVendor Advisory
FAQ
What is CVE-2013-4166?
CVE-2013-4166 is a vulnerability with a CVSS score of 7.5 (HIGH). The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email e...
How severe is CVE-2013-4166?
CVE-2013-4166 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-4166?
Check the references section above for vendor advisories and patch information. Affected products include: Gnome Evolution, Gnome Evolution Data Server, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, Redhat Enterprise Linux Workstation.