Gentoo Archives: gentoo-announce

From: Pierre-Yves Rofes <py@g.o>
To: gentoo-announce@l.g.o
Cc: full-disclosure@××××××××××××××.uk, bugtraq@×××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200806-06 ] Evolution: User-assisted execution of arbitrary code
Date: Mon, 16 Jun 2008 20:55:06
Message-Id: 4856D365.6020502@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200806-06
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Normal
11 Title: Evolution: User-assisted execution of arbitrary code
12 Date: June 16, 2008
13 Bugs: #223963
14 ID: 200806-06
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 Multiple vulnerabilities in Evolution may allow for user-assisted
22 execution of arbitrary code.
23
24 Background
25 ==========
26
27 Evolution is the mail client of the GNOME desktop environment.
28
29 Affected packages
30 =================
31
32 -------------------------------------------------------------------
33 Package / Vulnerable / Unaffected
34 -------------------------------------------------------------------
35 1 mail-client/evolution < 2.12.3-r2 >= 2.12.3-r2
36
37 Description
38 ===========
39
40 Alin Rad Pop (Secunia Research) reported two vulnerabilities in
41 Evolution:
42
43 * A boundary error exists when parsing overly long timezone strings
44 contained within iCalendar attachments and when the ITip formatter is
45 disabled (CVE-2008-1108).
46
47 * A boundary error exists when replying to an iCalendar request with
48 an overly long "DESCRIPTION" property while in calendar view
49 (CVE-2008-1109).
50
51 Impact
52 ======
53
54 A remote attacker could entice a user to open a specially crafted
55 iCalendar attachment, resulting in the execution of arbitrary code with
56 the privileges of the user running Evolution.
57
58 Workaround
59 ==========
60
61 There is no known workaround at this time.
62
63 Resolution
64 ==========
65
66 All Evolution users should upgrade to the latest version:
67
68 # emerge --sync
69 # emerge --ask --oneshot --verbose ">=mail-client/evolution-2.12.3-r2"
70
71 References
72 ==========
73
74 [ 1 ] CVE-2008-1108
75 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1108
76 [ 2 ] CVE-2008-1109
77 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1109
78
79 Availability
80 ============
81
82 This GLSA and any updates to it are available for viewing at
83 the Gentoo Security Website:
84
85 http://security.gentoo.org/glsa/glsa-200806-06.xml
86
87 Concerns?
88 =========
89
90 Security is a primary focus of Gentoo Linux and ensuring the
91 confidentiality and security of our users machines is of utmost
92 importance to us. Any security concerns should be addressed to
93 security@g.o or alternatively, you may file a bug at
94 http://bugs.gentoo.org.
95
96 License
97 =======
98
99 Copyright 2008 Gentoo Foundation, Inc; referenced text
100 belongs to its owner(s).
101
102 The contents of this document are licensed under the
103 Creative Commons - Attribution / Share Alike license.
104
105 http://creativecommons.org/licenses/by-sa/2.5
106 -----BEGIN PGP SIGNATURE-----
107 Version: GnuPG v2.0.7 (GNU/Linux)
108 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
109
110 iD8DBQFIVtNluhJ+ozIKI5gRAqwwAJ97oBXp0GtliSqRL/lh10E7gePmIgCggkL8
111 g6VvPANFxhxWuQnDw4K3UGI=
112 =B7py
113 -----END PGP SIGNATURE-----
114 --
115 gentoo-announce@l.g.o mailing list