PT-2005-1210 · Evolution+1 · Evolution+1

Max Vozeler

·

Published

2005-01-24

·

Updated

2024-02-08

·

CVE-2005-0102

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Evolution versions 2.0.2 and earlier
Description The issue allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1. This leads to a zero byte memory allocation and a buffer overflow in the camel-lock-helper.
Recommendations For Evolution versions 2.0.2 and earlier, update to a version later than 2.0.2 to resolve the issue. As a temporary workaround, consider restricting access to the camel-lock-helper until a patch is available.

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2005-0102
DSA-673-1
RHSA-2005:238
RHSA-2005:397
RHSA-2005_238
RHSA-2005_397

Affected Products

Evolution
Red Hat