what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 5 of 5 RSS Feed

CVE-2007-3257

Status Candidate

Overview

Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index.

Related Files

Gentoo Linux Security Advisory 200711-4
Posted Nov 7, 2007
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200711-04 - The imap_rescan() function of the file camel-imap-folder.c does not properly sanitize the SEQUENCE response sent by an IMAP server before being used to index arrays. Versions less than 1.10.3.1 are affected.

tags | advisory, imap
systems | linux, gentoo
advisories | CVE-2007-3257
SHA-256 | 6ab17f9c7332d6005a5f0de76d49e87be1e40ce82a77350dd6ded6d82833e4cc
Gentoo Linux Security Advisory 200707-3
Posted Jul 2, 2007
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200707-03 - The imap_rescan() function of the file camel-imap-folder.c does not properly sanitize the SEQUENCE response sent by an IMAP server before being used to index arrays. Versions less than 1.8.3-r5 are affected.

tags | advisory, imap
systems | linux, gentoo
advisories | CVE-2007-3257
SHA-256 | 22a437865c6384fb4f50131636f26fa027cfc76efb5aa54c54a3cc2898d7614c
Debian Linux Security Advisory 1325-1
Posted Jun 30, 2007
Authored by Debian | Site debian.org

Debian Security Advisory 1325-1 - Ulf Harnhammer discovered that a format string vulnerability in the handling of shared calendars may allow the execution of arbitrary code. It was discovered that the IMAP code in the Evolution Data Server performs insufficient sanitizing of a value later used an array index, which can lead to the execution of arbitrary code.

tags | advisory, arbitrary, imap
systems | linux, debian
advisories | CVE-2007-1002, CVE-2007-3257
SHA-256 | 68f3b62dbf023e6af4b70073b35b3629fbe220a2bf210b9990f274e68a88c888
Mandriva Linux Security Advisory 2007.136
Posted Jun 29, 2007
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory - A flaw in Evolution/evolution-data-server was found in how Evolution would process certain IMAP server messages. If a user were tricked into connecting to a malicious IMAP server, it was possible that arbitrary code could be executed with the privileges of the user using Evolution.

tags | advisory, arbitrary, imap
systems | linux, mandriva
advisories | CVE-2007-3257
SHA-256 | 157c59795abdb005555049836fc510295f4331a863c835c195aa1d976fb6f7f5
Ubuntu Security Notice 475-1
Posted Jun 26, 2007
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 475-1 - Philip Van Hoof discovered that the IMAP client in Evolution did not correctly verify the SEQUENCE value. A malicious or spoofed server could exploit this to execute arbitrary code with user privileges.

tags | advisory, arbitrary, spoof, imap
systems | linux, ubuntu
advisories | CVE-2007-3257
SHA-256 | ff622ba311e9c8544b1c98b631427e0bd81209035858f95156eb83039afc0983
Page 1 of 1
Back1Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close