Back

LOW

evolution: insecure permissions on evolution mailbox folders

Published May 14, 2009

Description

The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to local mail, which allows local users to obtain sensitive information by reading these files.

Affected products

Remediation

Red Hat statement

Red Hat does not consider this to be a security issue. By default, user home directories are created with mode 0700 permissions, which would not expose the ~/.evolution/ directory regardless of its own permissions. If a user intentionally relaxes permissions on their home directory, they should be auditing all files and directories in order to not expose unwanted files to other local users.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 14, 2009
Updated Aug 7, 2024
Reserved May 14, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date May 1, 2009