what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

evolution-dos.txt

evolution-dos.txt
Posted Jun 26, 2008
Authored by Juan Pablo Lopez Yacubian

Evolution version 2.22.2 suffers from a denial of service vulnerability.

tags | advisory, denial of service
SHA-256 | 17516bcf26c8d4f0da268aaddf236dd26adb91ee465e294179e93456aaf583df

evolution-dos.txt

Change Mirror Download

Application: Evolution 2.22.2
OS: Linux - Ubuntu 8.04
------------------------------------------------------
1 - Description
2 - Vulnerability
3 - POC/EXPLOIT


------------------------------------------------------
Description

Evolution is an email client that is built with ubuntu.


------------------------------------------------------
Vulnerability


The vulnerability works when mail is sent and specially armed with html code, this causes the client to break.

Analyzing with a debugger, you can see the failure with the following function.


0xb7a219d7 in html_engine_get_view_width () from /usr/lib/libgtkhtml-3.14.so.19


------------------------------------------------------
POC/EXPLOIT


The proof of concept can be done locally,
when you save the following code in a html file and then load it into an e-mail from the new option "insert" and "html file",
as that could verify the client is broken.

<IFRAME SRC="A"></IFRAME>
<FRAMESET><FRAME SRC="A"></FRAMESET>

------------------------------------------------------
Juan Pablo Lopez Yacubian
Login or Register to add favorites

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    25 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close