Gentoo Archives: gentoo-announce

From: Seemant Kulleen <seemant@g.o>
To: gentoo-announce@g.o, gentoo-security@g.o, lwn@×××.net
Subject: [gentoo-announce] Evolution memory bug
Date: Fri, 03 May 2002 17:30:47
Message-Id: 20020503153045.22c3b580.seemant@gentoo.org
1 - -----------------------------------------------------------------------
2 GLSA: GENTOO LINUX SECURITY ANNOUNCEMENT
3 - -----------------------------------------------------------------------
4 PACKAGE : evolution
5 SUMMARY : security vulnerability in evolution
6 DATE : Fri May 3 21:26:24 UTC 2002
7 - -----------------------------------------------------------------------
8
9 OVERVIEW
10
11 A security vulnerability has been found that might cause memory to be
12 eaten up due to malformed headers on incoming messages.
13
14
15 DETAIL
16
17 Fix for a security vulnerability that could allow a possible DOS due to
18 bad headers in incoming messages.
19 http://lists.gnome.org/archives/gnome-announce-list/2002-May/msg00020.html
20
21
22
23 SOLUTION
24
25 It is recommended that all Gentoo Linux users who are running evolution
26 update their systems as follows.
27
28 emerge --clean rsync
29 emerge evolution
30 emerge clean
31
32 - ------------------------------------------------------------------------
33 spider@g.o
34 seemant@g.o
35 drobbins@g.o
36 - ------------------------------------------------------------------------