PT-2009-6714 · Gnome+2 · Evolution Data Server+5

Diego Pettenò

+1

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2009-0587

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Evolution Data Server versions prior to 2.24.5 libedataserverui1.2-6 libedataserverui1.2-7 libedataserverui1.2-8 libedataserver1.2-7 libedataserver1.2-9 libedataserverui1.2-dev libedataserver1.2-dev libgdata1.2-1 libgdata1.2-dev
Description The issue involves multiple vulnerabilities in the Evolution Data Server and related packages in the Debian GNU/Linux operating system. These vulnerabilities can lead to disruptions in the confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be carried out remotely. The vulnerabilities include multiple integer overflows in the Evolution Data Server, which allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in certain files.
Recommendations For Evolution Data Server versions prior to 2.24.5, update to version 2.24.5 or later. For libedataserverui1.2-6, libedataserverui1.2-7, and libedataserverui1.2-8, consider disabling the affected packages until a patch is available. For libedataserver1.2-7 and libedataserver1.2-9, restrict access to the affected modules to minimize the risk of exploitation. For libedataserverui1.2-dev and libedataserver1.2-dev, avoid using the vulnerable functions until the issue is resolved. For libgdata1.2-1 and libgdata1.2-dev, consider applying configuration changes to mitigate the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability in some of the affected packages.

Fix

Weakness Enumeration

Related Identifiers

BDU:2015-03335
BDU:2015-03336
BDU:2015-03337
BDU:2015-03338
BDU:2015-03339
BDU:2015-03340
BDU:2015-03341
BDU:2015-03342
CVE-2009-0587
DSA-1813-1
RHSA-2009:0354
RHSA-2009:0355
RHSA-2009:0358
RHSA-2009_0354
RHSA-2009_0355

Affected Products

Debian
Evolution Data Server
Red Hat
Libedataserver
Libedataserverui1.2
Libgdata