Secunia Security Advisory - Ulf Harnhammar has reported some vulnerabilities in Evolution, which can be exploited by malicious people to compromise a vulnerable system.
ecc096d26115c9f59c55ea8d32bc98c9b20685a42f713f4bb21a06de6fb599cb
----------------------------------------------------------------------
Bist Du interessiert an einem neuen Job in IT-Sicherheit?
Secunia hat zwei freie Stellen als Junior und Senior Spezialist in IT-
Sicherheit:
http://secunia.com/secunia_vacancies/
----------------------------------------------------------------------
TITLE:
GNOME Evolution Multiple Format String Vulnerabilities
SECUNIA ADVISORY ID:
SA16394
VERIFY ADVISORY:
http://secunia.com/advisories/16394/
CRITICAL:
Highly critical
IMPACT:
System access
WHERE:
>From remote
SOFTWARE:
GNOME Evolution 1.x
http://secunia.com/product/5524/
GNOME Evolution 2.x
http://secunia.com/product/5525/
DESCRIPTION:
Ulf Harnhammar has reported some vulnerabilities in Evolution, which
can be exploited by malicious people to compromise a vulnerable
system.
1) A format string error when displaying full vCard information
attached to an e-mail message can be exploited to execute arbitrary
code.
Successful exploitation requires that the user clicks on "Show Full
vCard" or saves the vCard to an address book and then views it under
the "Contacts" tab.
2) A format string error exists when displaying specially crafted
contact data retrieved from an LDAP server.
3) A format string error exists when displaying specially crafted
task list data retrieved from remote servers and when the user saves
the task list data under the "Calendars" tab.
The vulnerabilities have been reported in versions 1.5 through
2.3.6.1.
SOLUTION:
The vulnerabilities have reportedly been fixed in 2.3.7 (unstable).
PROVIDED AND/OR DISCOVERED BY:
Ulf Harnhammar
ORIGINAL ADVISORY:
SITIC:
http://www.sitic.se/eng/advisories_and_recommendations/sa05-001.html
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------