PT-2007-4536 · Gnome+1 · Evolution Data Server+1

Published

2007-06-19

·

Updated

2024-06-15

·

CVE-2007-3257

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Evolution Data Server version 1.11
Description The issue allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index. This is due to a flaw in the camel-imap-folder.c file within the mailer component.
Recommendations For Evolution Data Server version 1.11, consider disabling the IMAP functionality until a patch is available to prevent potential exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3257
DSA-1321-1
DSA-1325-1
OPENSUSE-SU-2024:10744-1
RHSA-2007:0509
RHSA-2007:0510
RHSA-2007_0509
RHSA-2007_0510

Affected Products

Evolution Data Server
Red Hat