security advisorycriticalcode execution
Critical: evolution security update. Date: Wed, 5 Mar 2008 16:24:21 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for evolution on SL4.x, SL5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Critical: evolution security update Issue date: 2008-03-05 CVE Names: CVE-2008-0072 A format string flaw was found in the way Evolution displayed encrypted mail content. If a user opened a carefully crafted mail message, arbitrary code could be executed as the user running Evolution. (CVE-2008-0072) SL 4.x SRPMS: evolution-2.0.2-35.0.4.el4_6.1.src.rpm i386: evolution-2.0.2-35.0.4.el4_6.1.i386.rpm evolution-devel-2.0.2-35.0.4.el4_6.1.i386.rpm x86_64: evolution-2.0.2-35.0.4.el4_6.1.x86_64.rpm evolution-devel-2.0.2-35.0.4.el4_6.1.x86_64.rpm SL 5.x SRPMS: evolution-2.8.0-40.el5_1.1.src.rpm i386: evolution-2.8.0-40.el5_1.1.i386.rpm evolution-devel-2.8.0-40.el5_1.1.i386.rpm x86_64: evolution-2.8.0-40.el5_1.1.i386.rpm evolution-2.8.0-40.el5_1.1.x86_64.rpm evolution-devel-2.8.0-40.el5_1.1.i386.rpm evolution-devel-2.8.0-40.el5_1.1.x86_64.rpm -Connie Sieh -Troy Dawson . An important security patch for Evolution resolves a format string vulnerability that may lead to code execution. Update required!. Evolution Security Update, Scientific Linux Critical Advisory, Code Execution Flaw. . Severity: Critical. LinuxSecurity.com Team
Mar 05, 2008
•Critical
Scientific Linux