Lucene search

K
centosCentOS ProjectCESA-2007:0509
HistoryJun 25, 2007 - 2:45 p.m.

evolution security update

2007-06-2514:45:34
CentOS Project
lists.centos.org
39

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.03

Percentile

91.0%

CentOS Errata and Security Advisory CESA-2007:0509

Evolution is the GNOME collection of personal information management (PIM)
tools.

A flaw was found in the way Evolution processes certain IMAP server
messages. If a user can be tricked into connecting to a malicious IMAP
server it may be possible to execute arbitrary code as the user running
evolution. (CVE-2007-3257)

All users of Evolution should upgrade to these updated packages, which
contain a backported patch which resolves this issue.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2007-June/076134.html
https://lists.centos.org/pipermail/centos-announce/2007-June/076135.html
https://lists.centos.org/pipermail/centos-announce/2007-June/076140.html
https://lists.centos.org/pipermail/centos-announce/2007-June/076141.html
https://lists.centos.org/pipermail/centos-announce/2007-June/076167.html
https://lists.centos.org/pipermail/centos-announce/2007-June/076170.html
https://lists.centos.org/pipermail/centos-announce/2007-June/076176.html
https://lists.centos.org/pipermail/centos-announce/2007-June/076177.html

Affected packages:
evolution
evolution-devel

Upstream details at:
https://access.redhat.com/errata/RHSA-2007:0509

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.03

Percentile

91.0%