CVE-2013-4166

NameCVE-2013-4166
DescriptionThe gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
evolution (PTS)bullseye (security), bullseye3.38.3-1+deb11u2vulnerable
bookworm3.46.4-2vulnerable
bookworm (security)3.46.4-2+deb12u1vulnerable
trixie3.56.1-1vulnerable
trixie (security)3.56.1-1+deb13u1vulnerable
forky3.56.2-5vulnerable
sid3.56.2-7vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
evolutionsource(unstable)(unfixed)unimportant

Notes

Regular UI bug, not a security issue.

Search for package or bug name: Reporting problems