Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Evolution | Gnome | 1.5 (including) | 1.5 (including) |
Evolution | Gnome | 2.0 (including) | 2.0 (including) |
Evolution | Gnome | 2.1 (including) | 2.1 (including) |
Evolution | Gnome | 2.2 (including) | 2.2 (including) |
Evolution | Gnome | 2.3.1 (including) | 2.3.1 (including) |
Evolution | Gnome | 2.3.2 (including) | 2.3.2 (including) |
Evolution | Gnome | 2.3.3 (including) | 2.3.3 (including) |
Evolution | Gnome | 2.3.4 (including) | 2.3.4 (including) |
Evolution | Gnome | 2.3.5 (including) | 2.3.5 (including) |
Evolution | Gnome | 2.3.6.1 (including) | 2.3.6.1 (including) |
Red Hat Enterprise Linux 3 | RedHat | evolution-0:1.4.5-16 | * |
Red Hat Enterprise Linux 4 | RedHat | evolution-0:2.0.2-16.3 | * |