CVE-2013-4166

NameCVE-2013-4166
DescriptionThe gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
evolution (PTS)bullseye3.38.3-1+deb11u2vulnerable
bullseye (security)3.38.3-1+deb11u3vulnerable
bookworm3.46.4-2vulnerable
bookworm (security)3.46.4-2+deb12u1vulnerable
trixie3.56.2-0+deb13u1vulnerable
trixie (security)3.56.1-1+deb13u1vulnerable
forky, sid3.56.2-7vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
evolutionsource(unstable)(unfixed)unimportant

Notes

Regular UI bug, not a security issue.

Search for package or bug name: Reporting problems