News

Referenced CVEs:
CVE-2007-1002
Description:
=========================================================== Ubuntu Security Notice USN-442-1 March 26, 2007 evolution vulnerability CVE-2007-1002 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 6.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: evolution 2.6.1-0ubuntu7.1 Ubuntu 6.10: evolution 2.8.1-0ubuntu4.1 After a standard system upgrade you need to restart Evolution or reboot your computer to effect the necessary changes. Details follow: Ulf Harnhammar of Secunia Research discovered that Evolution did not correctly handle format strings when displaying shared memos. If a remote attacker tricked a user into viewing a specially crafted shared memo, they could execute arbitrary code with user privileges.