CVE-2003-0130
EPSS 10.3%
描述
The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers to inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.
如何修補 CVE-2003-0130
要修補 CVE-2003-0130,請將受影響套件升級到下列已修補版本。
- Debian/evolution—升級至 1.2.3 或更新版本
CVE-2003-0130 正在被利用嗎?
中等 — EPSS 為 10.3%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 1.2.3