*** This bug is a security vulnerability ***

Public security bug reported:

Binary package hint: evolution

CVE-2008-1108 description:

"Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is
disabled, allows remote attackers to execute arbitrary code via a long
timezone string in an iCalendar attachment."

CVE-2008-1109 description:

"Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted
remote attackers to execute arbitrary code via a long DESCRIPTION
property in an iCalendar attachment, which is not properly handled
during a reply in the calendar view (aka the Calendars window)."

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1108
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1109
http://secunia.com/advisories/30298

** Affects: evolution (Ubuntu)
     Importance: Undecided
         Status: New

** Visibility changed to: Public

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-1108

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-1109

-- 
[CVE-2008-1108, CVE-2008-1109] Evolution iCalendar buffer overflows
https://bugs.launchpad.net/bugs/237956
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to evolution in ubuntu.

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

Reply via email to