Submitted by KeesCook on Mon, 2005-01-24 12:01
Referenced CVEs:
CAN-2005-0102
Description:
===========================================================
Ubuntu Security Notice USN-69-1 January 24, 2005
evolution vulnerability
CAN-2005-0102
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 4.10 (Warty Warthog)
The following packages are affected:
evolution
The problem can be corrected by upgrading the affected package to
version 2.0.2-0ubuntu2.1. In general, a standard system upgrade is
sufficient to effect the necessary changes.
Details follow:
Max Vozeler discovered an integer overflow in camel-lock-helper. An
user-supplied length value was not validated, so that a value of -1
caused a buffer allocation of 0 bytes; this buffer was then filled by
an arbitrary amount of user-supplied data.
A local attacker or a malicious POP3 server could exploit this to
execute arbitrary code with root privileges (because camel-lock-helper
is installed as setuid root).


