PT-2009-6712 · Debian+2 · Debian+4
Jan Lieskovsky
·
Published
1970-01-01
·
Updated
2017-09-29
·
CVE-2009-0547
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libedataserverui1.2-8
libgdata1.2-dev
libedataserver1.2-7
libedataserverui1.2-6
libgdata1.2-1
libedataserverui1.2-dev
libedataserver1.2-9
libedataserver1.2-dev
Evolution version 2.22.3.1
Description
The issue concerns multiple vulnerabilities in various packages of the Debian GNU/Linux operating system, including libedataserverui1.2, libgdata1.2, and libedataserver1.2, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Additionally, there is a vulnerability in Evolution 2.22.3.1 that allows remote attackers to spoof S/MIME signatures by modifying the copy of the e-mail text displayed to the user.
Recommendations
For libedataserverui1.2-8, consider updating to a newer version to mitigate the risk.
For libgdata1.2-dev, consider updating to a newer version to mitigate the risk.
For libedataserver1.2-7, consider updating to a newer version to mitigate the risk.
For libedataserverui1.2-6, consider updating to a newer version to mitigate the risk.
For libgdata1.2-1, consider updating to a newer version to mitigate the risk.
For libedataserverui1.2-dev, consider updating to a newer version to mitigate the risk.
For libedataserver1.2-9, consider updating to a newer version to mitigate the risk.
For libedataserver1.2-dev, consider updating to a newer version to mitigate the risk.
For Evolution version 2.22.3.1, consider updating to a newer version to mitigate the risk of S/MIME signature spoofing.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Evolution
Red Hat
Libedataserverui1.2
Libgdata1.2