Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Linux All distros and thier applications

Reply
 
Thread Tools Display Modes
  #1  
Old 06-10-2008, 07:05 PM
Mandriva's Avatar
Mandriva Mandriva is offline
Senior Member
 
Join Date: Oct 2006
Posts: 720
Mandriva- Advisories MDVSA-2008:111: Updated Evolution packages fix vulnerabilities

Advisories MDVSA-2008:111: Updated Evolution packages fix vulnerabilities
Alan Rad Pop of Secunia Research discovered the following two
vulnerabilities in Evolution:

Evolution did not properly validate timezone data when processing
iCalendar attachments. If a user disabled the Itip Formatter plugin
and viewed a crafted iCalendar attachment, an attacker could cause
a denial of service or potentially execute arbitrary code with the
user's privileges (CVE-2008-1108).

Evolution also did not properly validate the DESCRIPTION field when
processing iCalendar attachments. If a user were tricked into
accepting a crafted iCalendar attachment and replied to it from
the calendar window, an attacker could cause a denial of service
or potentially execute arbitrary code with the user's privileges
(CVE-2008-1109).

In addition, Matej Cepl found that Evolution did not properly validate
date fields when processing iCalendar attachments, which could lead to
a denial of service if the user viewed a crafted iCalendar attachment
with the Itip Formatter plugin disabled.

Mandriva Linux has the Itip Formatter plugin enabled by default.

The updated packages have been patched to prevent these issues.
http://mandrivausers.org/index.php?showtopic=60664
http://mandrivausers.org/index.php?showtopic=60664
Tue, 10 Jun 2008 21:00:32 +0000
Reply With Quote
Posted


Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is On
    Forum Jump



    All times are GMT -5. The time now is 11:06 PM.


    Firefox 2