CVE Vulnerabilities

CVE-2005-2549

Published: Aug 12, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.

Affected Software

NameVendorStart VersionEnd Version
EvolutionGnome1.5 (including)1.5 (including)
EvolutionGnome2.0 (including)2.0 (including)
EvolutionGnome2.1 (including)2.1 (including)
EvolutionGnome2.2 (including)2.2 (including)
EvolutionGnome2.3.1 (including)2.3.1 (including)
EvolutionGnome2.3.2 (including)2.3.2 (including)
EvolutionGnome2.3.3 (including)2.3.3 (including)
EvolutionGnome2.3.4 (including)2.3.4 (including)
EvolutionGnome2.3.5 (including)2.3.5 (including)
EvolutionGnome2.3.6.1 (including)2.3.6.1 (including)
Red Hat Enterprise Linux 3RedHatevolution-0:1.4.5-16*
Red Hat Enterprise Linux 4RedHatevolution-0:2.0.2-16.3*

References