CVE-2013-4166

NameCVE-2013-4166
DescriptionThe gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
evolution (PTS)jessie, jessie (lts)3.12.9~git20141130.241663-1+deb8u1vulnerable
stretch (security), stretch (lts), stretch3.22.6-1+deb9u2vulnerable
buster3.30.5-1.1vulnerable
bullseye (security), bullseye3.38.3-1+deb11u2vulnerable
bookworm3.46.4-2vulnerable
sid, trixie3.50.3-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
evolutionsource(unstable)(unfixed)unimportant

Notes

Regular UI bug, not a security issue.

Search for package or bug name: Reporting problems