Submitted by KeesCook on Mon, 2007-03-26 19:31.
usn
Referenced CVEs:
CVE-2007-1002
Description:
===========================================================
Ubuntu Security Notice USN-442-1 March 26, 2007
evolution vulnerability
CVE-2007-1002
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
evolution 2.6.1-0ubuntu7.1
Ubuntu 6.10:
evolution 2.8.1-0ubuntu4.1
After a standard system upgrade you need to restart Evolution or reboot
your computer to effect the necessary changes.
Details follow:
Ulf Harnhammar of Secunia Research discovered that Evolution did not
correctly handle format strings when displaying shared memos. If a
remote attacker tricked a user into viewing a specially crafted shared
memo, they could execute arbitrary code with user privileges.


