Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.55177
Category:FreeBSD Local Security Checks
Title:FreeBSD Ports: evolution
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to the system
as announced in the referenced advisory.

The following package is affected: evolution

CVE-2005-2549
Multiple format string vulnerabilities in Evolution 1.5 through
2.3.6.1 allow remote attackers to cause a denial of service (crash)
and possibly execute arbitrary code via (1) full vCard data, (2)
contact data from remote LDAP servers, or (3) task list data from
remote servers.

CVE-2005-2550
Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows
remote attackers to cause a denial of service (crash) and possibly
execute arbitrary code via the calendar entries such as task lists,
which are not properly handled when the user selects the Calendars
tab.

Solution:
Update your system with the appropriate patches or
software upgrades.

http://www.sitic.se/eng/advisories_and_recommendations/sa05-001.html
http://www.vuxml.org/freebsd/e5afdf63-1746-11da-978e-0001020eed82.html

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-2549
BugTraq ID: 14532
http://www.securityfocus.com/bid/14532
Bugtraq: 20050810 Evolution multiple remote format string bugs (Google Search)
http://www.securityfocus.com/archive/1/407789
Debian Security Information: DSA-1016 (Google Search)
http://www.debian.org/security/2006/dsa-1016
http://www.redhat.com/archives/fedora-announce-list/2005-August/msg00031.html
http://marc.info/?l=full-disclosure&m=112368237712032&w=2
http://www.mandriva.com/security/advisories?name=MDKSA-2005:141
http://www.sitic.se/eng/advisories_and_recommendations/sa05-001.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9553
http://www.redhat.com/support/errata/RHSA-2005-267.html
http://secunia.com/advisories/16394
http://secunia.com/advisories/19380
SuSE Security Announcement: SUSE-SA:2005:054 (Google Search)
http://www.novell.com/linux/security/advisories/2005_54_evolution.html
https://usn.ubuntu.com/166-1/
Common Vulnerability Exposure (CVE) ID: CVE-2005-2550
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10880
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.