Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Critical Security Update for Evolution-Data-Server in Scientific Linux 5.x

Scientific Large Esm H500
Important: evolution-data-server security update
Date: Tue, 26 Jun 2007 16:23:29 -0500
Reply-To: Troy Dawson 
Sender: Security Errata for Scientific Linux
 
From: Troy Dawson 
Subject: Security ERRATA for on SL5.x i386/x86_64
Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it.

Synopsis:	Important: evolution-data-server security update
Issue date:	 2007-06-25
CVE Names:	CVE-2007-3257

A flaw was found in the way evolution-data-server processes certain IMAP
server messages. If a user can be tricked into connecting to a malicious
IMAP server it may be possible to execute arbitrary code as the user
running the evolution-data-server process. (CVE-2007-3257)

Evolution crushed in first-time wizard stage for timezones: Europe/Moscow,
Europe/Volgograd, Asia/Irkutsk, Asia/Makassar, Asia/Ujung_Pandang,
Asia/Ulaanbaatar, Asia/Ulan_Bator. This bug is a consequence of removing TZNAME
tag from timezone ICS VCARDs.

SL 5.x

 SRPMS:
	evolution-data-server-1.8.0-15.0.4.1.sl5.src.rpm
 i386:
	evolution-data-server-1.8.0-15.0.4.1.sl5.i386.rpm
	evolution-data-server-devel-1.8.0-15.0.4.1.sl5.i386.rpm
 x86_64:
	evolution-data-server-1.8.0-15.0.4.1.sl5.i386.rpm
	evolution-data-server-1.8.0-15.0.4.1.sl5.x86_64.rpm
	evolution-data-server-devel-1.8.0-15.0.4.1.sl5.i386.rpm
	evolution-data-server-devel-1.8.0-15.0.4.1.sl5.x86_64.rpm

-Connie Sieh
-Troy Dawson
Your message here