{"id":"CVE-2012-1103","details":"emacs/notmuch-mua.el in Notmuch before 0.11.1, when using the Emacs interface, allows user-assisted remote attackers to read arbitrary files via crafted MML tags, which are not properly quoted in an email reply cna cause the files to be attached to the message.","modified":"2026-01-27T04:11:05.639815Z","published":"2012-09-25T23:55:01Z","withdrawn":"2026-01-27T04:11:05.639815Z","references":[{"type":"ADVISORY","url":"http://notmuchmail.org/news/release-0.11.1/"},{"type":"ADVISORY","url":"http://secunia.com/advisories/48139"},{"type":"ADVISORY","url":"http://www.debian.org/security/2012/dsa-2416"},{"type":"FIX","url":"http://git.notmuchmail.org/git/notmuch/blobdiff/3f2050ac221a4c940c12442f156f12fff11600c6..ae438ccd8c77831158c7c30f19710d798ee4a6b4:/emacs/notmuch-mua.el"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2012/03/04/5"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2012/03/05/6"},{"type":"WEB","url":"http://www.securityfocus.com/bid/52155"}],"schema_version":"1.7.3"}