Evolution is a GNOME-based collection of personal information management
(PIM) tools.
A bug was found in the way Evolution displays mail messages. It is possible
that an attacker could create a specially crafted mail message that when
opened by a victim causes Evolution to stop responding. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0806 to this issue.
A bug was also found in Evolution’s helper program camel-lock-helper. This
bug could allow a local attacker to gain root privileges if
camel-lock-helper has been built to execute with elevated privileges. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0102 to this issue. On Red Hat Enterprise Linux,
camel-lock-helper is not built to execute with elevated privileges by
default. Please note however that if users have rebuilt Evolution from the
source RPM, as the root user, camel-lock-helper may be given elevated
privileges.
All users of evolution should upgrade to these updated packages, which
include backported fixes to correct these issues.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
RedHat | any | ppc | evolution-devel | < 2.0.2-16 | evolution-devel-2.0.2-16.ppc.rpm |
RedHat | any | ia64 | evolution-devel | < 2.0.2-16 | evolution-devel-2.0.2-16.ia64.rpm |
RedHat | any | x86_64 | evolution | < 2.0.2-16 | evolution-2.0.2-16.x86_64.rpm |
RedHat | any | ppc | evolution | < 2.0.2-16 | evolution-2.0.2-16.ppc.rpm |
RedHat | any | s390x | evolution | < 2.0.2-16 | evolution-2.0.2-16.s390x.rpm |
RedHat | any | ia64 | evolution | < 2.0.2-16 | evolution-2.0.2-16.ia64.rpm |
RedHat | any | src | evolution | < 2.0.2-16 | evolution-2.0.2-16.src.rpm |
RedHat | any | i386 | evolution-devel | < 2.0.2-16 | evolution-devel-2.0.2-16.i386.rpm |
RedHat | any | s390 | evolution | < 2.0.2-16 | evolution-2.0.2-16.s390.rpm |
RedHat | any | x86_64 | evolution-devel | < 2.0.2-16 | evolution-devel-2.0.2-16.x86_64.rpm |