Lucene search

K
centosCentOS ProjectCESA-2007:0353
HistoryMay 17, 2007 - 4:27 p.m.

evolution security update

2007-05-1716:27:09
CentOS Project
lists.centos.org
44

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

EPSS

0.088

Percentile

94.6%

CentOS Errata and Security Advisory CESA-2007:0353

Evolution is the GNOME collection of personal information management (PIM)
tools.

A flaw was found in the way Evolution processed certain APOP authentication
requests. A remote attacker could potentially acquire certain portions of a
user’s authentication credentials by sending certain responses when
evolution-data-server attempted to authenticate against an APOP server.
(CVE-2007-1558)

All users of Evolution should upgrade to these updated packages, which
contain a backported patch which resolves this issue.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2007-May/075929.html
https://lists.centos.org/pipermail/centos-announce/2007-May/075931.html
https://lists.centos.org/pipermail/centos-announce/2007-May/075935.html
https://lists.centos.org/pipermail/centos-announce/2007-May/075936.html
https://lists.centos.org/pipermail/centos-announce/2007-May/075946.html
https://lists.centos.org/pipermail/centos-announce/2007-May/075947.html
https://lists.centos.org/pipermail/centos-announce/2007-May/075954.html
https://lists.centos.org/pipermail/centos-announce/2007-May/075957.html

Affected packages:
evolution
evolution-devel

Upstream details at:
https://access.redhat.com/errata/RHSA-2007:0353

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

EPSS

0.088

Percentile

94.6%