|
|
|
![]() |
Vulnerability Note VU#512491GNOME Evolution format string vulnerabilityOverviewThe GNOME Evolution mail client contains a format string vulnerability that may allow an attacker to execute code.I. DescriptionEvolution is the default mail client for the GNOME desktop environment. Evolution supports both GPG and S/MIME mail encryption.From Secunia Advisory SA29057:
Successful exploitation requires that the user selects a malicious e-mail message. II. ImpactA remote, unauthenticated attacker may be able to execute arbitrary code or cause Evolution to crash.III. SolutionUpgradeThe Evolution team has released a patch to address this issue. See GNOME Bug 520745 for more information. Users and administrators who do not compile Evolution from source should obtain fixed software from their operating system vendor.
References
This vulnerability was made public by Ulf Harnhammar of Secunia Research. This document was written by Ryan Giobbi.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||||||||