Ubuntu Security Notice USN-583-1
5th March, 2008
evolution vulnerability
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 7.10
- Ubuntu 7.04
- Ubuntu 6.10
- Ubuntu 6.06 LTS
Software description
- evolution
Details
Ulf Harnhammar discovered that Evolution did not correctly handle format
strings when processing encrypted emails. A remote attacker could exploit
this by sending a specially crafted email, resulting in arbitrary code
execution.
Update instructions
The problem can be corrected by updating your system to the following package version:
- Ubuntu 7.10:
- evolution 2.12.1-0ubuntu1.1
- Ubuntu 7.04:
- evolution 2.10.1-0ubuntu2.1
- Ubuntu 6.10:
- evolution 2.8.1-0ubuntu4.2
- Ubuntu 6.06 LTS:
- evolution 2.6.1-0ubuntu7.2
To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.
After a standard system upgrade you need to restart Evolution to effect
the necessary changes.