CVE-2005-2549
CVE-2005-2549
Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://marc.info/?l=full-disclosure&m=112368237712032&w=2http://secunia.com/advisories/16394http://secunia.com/advisories/19380https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9553https://usn.ubuntu.com/166-1/http://www.debian.org/security/2006/dsa-1016http://www.mandriva.com/security/advisories?name=MDKSA-2005:141http://www.novell.com/linux/security/advisories/2005_54_evolution.htmlhttp://www.redhat.com/archives/fedora-announce-list/2005-August/msg00031.htmlhttp://www.redhat.com/support/errata/RHSA-2005-267.htmlhttp://www.securityfocus.com/archive/1/407789http://www.securityfocus.com/bid/14532