CVE-2013-4166
published 2020-02-06CVE-2013-4166: The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.89%
77.3th percentile
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | evolution | — | — |
| gnome | evolution | <= 3.8.4 | — |
| gnome | evolution | — | — |
| gnome | evolution_data_server | <= 3.9.5 | — |
| gnome | evolution_data_server | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Evolution Data Server vulnerability
vendor_ubuntu·2013-07-31
CVE-2013-4166 Evolution Data Server vulnerability
Title: Evolution Data Server vulnerability
Summary: Evolution would sometimes encrypt email to the wrong recipient.
Yves-Alexis Perez discovered that Evolution Data Server did not properly
select GPG recipients. Under certain circumstances, this could result in
Evolution encrypting email to an unintended recipient.
Instructions: After a standard system update you need to restart Evolution to make all
the necessary changes.
Red Hat
evolution: incorrect selection of recipient gpg public key for encrypted mail
vendor_redhat·2013-07-22·CVSS 7.5
CVE-2013-4166 [HIGH] CWE-697 evolution: incorrect selection of recipient gpg public key for encrypted mail
evolution: incorrect selection of recipient gpg public key for encrypted mail
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Package: evolution (Red H
Debian
CVE-2013-4166: evolution - The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evoluti...
vendor_debian·2013·CVSS 7.5
CVE-2013-4166 [HIGH] CVE-2013-4166: evolution - The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evoluti...
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-p34q-c63v-mp3m: The gpg_ctx_add_recipient function in camel/camel-gpg-context
ghsa_unreviewed·2022-05-05
CVE-2013-4166 [MEDIUM] CWE-200 GHSA-p34q-c63v-mp3m: The gpg_ctx_add_recipient function in camel/camel-gpg-context
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.
OSV
CVE-2013-4166: The gpg_ctx_add_recipient function in camel/camel-gpg-context
osv·2020-02-06·CVSS 7.5
CVE-2013-4166 [HIGH] CVE-2013-4166: The gpg_ctx_add_recipient function in camel/camel-gpg-context
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2013-1540.htmlhttp://seclists.org/oss-sec/2013/q3/191https://bugzilla.redhat.com/show_bug.cgi?id=973728https://git.gnome.org/browse/evolution-data-server/commit/?h=gnome-3-8&id=f7059bb37dcce485d36d769142ec9515708d8ae5https://git.gnome.org/browse/evolution-data-server/commit/?id=5d8b92c622f6927b253762ff9310479dd3ac627dhttp://rhn.redhat.com/errata/RHSA-2013-1540.htmlhttp://seclists.org/oss-sec/2013/q3/191https://bugzilla.redhat.com/show_bug.cgi?id=973728https://git.gnome.org/browse/evolution-data-server/commit/?h=gnome-3-8&id=f7059bb37dcce485d36d769142ec9515708d8ae5https://git.gnome.org/browse/evolution-data-server/commit/?id=5d8b92c622f6927b253762ff9310479dd3ac627d
2020-02-06
Published