Novell Evolution Camel-Lock-Helper Application Remote Integer Overflow Vulnerability
BID:12354
Info
Novell Evolution Camel-Lock-Helper Application Remote Integer Overflow Vulnerability
| Bugtraq ID: | 12354 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-0102 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 24 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | Discovery of this vulnerability is credited to Max Vozeler. |
| Vulnerable: |
Ximian Evolution 1.3.2 (beta) Ximian Evolution 1.2.4 Ximian Evolution 1.2.3 Ximian Evolution 1.2.2 Ximian Evolution 1.2.1 Ximian Evolution 1.2 Ximian Evolution 1.1.1 Ximian Evolution 1.0.8 Ximian Evolution 1.0.7 Ximian Evolution 1.0.6 Ximian Evolution 1.0.5 Ximian Evolution 1.0.4 Ximian Evolution 1.0.3 Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 SuSE Linux 8.1 SuSE Linux 8.0 i386 SuSE Linux 8.0 SGI ProPack 3.0 SGI Advanced Linux Environment 3.0 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 3 Redhat Desktop 3.0 Novell Evolution 2.0.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 ALT Linux ALT Linux Junior 2.3 ALT Linux ALT Linux Compact 2.3 |
| Not Vulnerable: | |
Discussion
Novell Evolution Camel-Lock-Helper Application Remote Integer Overflow Vulnerability
The Evolution camel-lock-helper application is reported prone to an integer overflow vulnerability. The issue is reported to exist in the main() function of the 'camel-lock-helper.c' source file.
A remote attacker may exploit this vulnerability to execute arbitrary code.
The Evolution camel-lock-helper application is reported prone to an integer overflow vulnerability. The issue is reported to exist in the main() function of the 'camel-lock-helper.c' source file.
A remote attacker may exploit this vulnerability to execute arbitrary code.
Exploit / POC
Novell Evolution Camel-Lock-Helper Application Remote Integer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Novell Evolution Camel-Lock-Helper Application Remote Integer Overflow Vulnerability
Solution:
Mandrake has released a security advisory (MDKSA-2005:024) and fixes to address this vulnerability. Please see the referenced advisory for further information regarding obtaining and applying fixes.
Ubuntu has released a security advisory (USN-69-1 ) and fixes to address this vulnerability. Please see the referenced advisory for further information regarding obtaining and applying fixes.
Gentoo has released an advisory (GLSA 200501-35) and an updated eBuild to address this vulnerability. Gentoo users are advised to issue the following sequence of commands as a superuser in order to apply the fixes:
emerge --sync
emerge --ask --oneshot --verbose ">=mail-client/evolution-2.0.2-r1"
SuSE Linux has released a security summary report (SUSE-SR:2005:003) that contains fixes to address this and other vulnerabilities. Customers are advised to peruse the referenced advisory for further information regarding obtaining and applying appropriate updates.
Debian has released a security advisory (DSA 673-1) and fixes to address this vulnerability. Please see the referenced advisory for further information regarding obtaining and applying fixes.
Conectiva Linux has released advisory CLA-2005:925 along with an upgrade dealing with this issue. Please see the referenced advisory for more information.
ALT Linux has released updates dealing with this and other issues. Please see the reference section for more information.
RedHat has released advisory RHSA-2005:238-18, along with fixes to address this issue in RedHat Enterprise Linux. Please see the referenced advisory for further information.
SGI has released advisory 20050503-01-U, along with SGI Advanced Linux Environment 3 Security Update #38 to address this, and other issues. Please see the referenced advisory for further information.
Ximian Evolution 1.0.5
Mandriva Linux Mandrake 10.0
Mandriva Linux Mandrake 10.0 AMD64
Mandriva Linux Mandrake 10.1
Mandriva Linux Mandrake 10.1 x86_64
Novell Evolution 2.0.2
MandrakeSoft Corporate Server 3.0 x86_64
MandrakeSoft Corporate Server 3.0
SuSE Linux 8.1
S.u.S.E. Linux Personal 8.2
S.u.S.E. Linux Personal 9.0
S.u.S.E. Linux Personal 9.0 x86_64
S.u.S.E. Linux Personal 9.1
S.u.S.E. Linux Personal 9.2
Solution:
Mandrake has released a security advisory (MDKSA-2005:024) and fixes to address this vulnerability. Please see the referenced advisory for further information regarding obtaining and applying fixes.
Ubuntu has released a security advisory (USN-69-1 ) and fixes to address this vulnerability. Please see the referenced advisory for further information regarding obtaining and applying fixes.
Gentoo has released an advisory (GLSA 200501-35) and an updated eBuild to address this vulnerability. Gentoo users are advised to issue the following sequence of commands as a superuser in order to apply the fixes:
emerge --sync
emerge --ask --oneshot --verbose ">=mail-client/evolution-2.0.2-r1"
SuSE Linux has released a security summary report (SUSE-SR:2005:003) that contains fixes to address this and other vulnerabilities. Customers are advised to peruse the referenced advisory for further information regarding obtaining and applying appropriate updates.
Debian has released a security advisory (DSA 673-1) and fixes to address this vulnerability. Please see the referenced advisory for further information regarding obtaining and applying fixes.
Conectiva Linux has released advisory CLA-2005:925 along with an upgrade dealing with this issue. Please see the referenced advisory for more information.
ALT Linux has released updates dealing with this and other issues. Please see the reference section for more information.
RedHat has released advisory RHSA-2005:238-18, along with fixes to address this issue in RedHat Enterprise Linux. Please see the referenced advisory for further information.
SGI has released advisory 20050503-01-U, along with SGI Advanced Linux Environment 3 Security Update #38 to address this, and other issues. Please see the referenced advisory for further information.
Ximian Evolution 1.0.5
-
Debian evolution_1.0.5-1woody2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0 .5-1woody2_alpha.deb -
Debian evolution_1.0.5-1woody2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0 .5-1woody2_arm.deb -
Debian evolution_1.0.5-1woody2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0 .5-1woody2_i386.deb -
Debian evolution_1.0.5-1woody2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0 .5-1woody2_ia64.deb -
Debian evolution_1.0.5-1woody2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0 .5-1woody2_m68k.deb -
Debian evolution_1.0.5-1woody2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0 .5-1woody2_powerpc.deb -
Debian evolution_1.0.5-1woody2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0 .5-1woody2_s390.deb -
Debian evolution_1.0.5-1woody2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/evolution_1.0 .5-1woody2_sparc.deb -
Debian libcamel-dev_1.0.5-1woody2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/libcamel-dev_ 1.0.5-1woody2_alpha.deb -
Debian libcamel-dev_1.0.5-1woody2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/libcamel-dev_ 1.0.5-1woody2_arm.deb -
Debian libcamel-dev_1.0.5-1woody2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/libcamel-dev_ 1.0.5-1woody2_i386.deb -
Debian libcamel-dev_1.0.5-1woody2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/libcamel-dev_ 1.0.5-1woody2_ia64.deb -
Debian libcamel-dev_1.0.5-1woody2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/libcamel-dev_ 1.0.5-1woody2_m68k.deb -
Debian libcamel-dev_1.0.5-1woody2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/libcamel-dev_ 1.0.5-1woody2_powerpc.deb -
Debian libcamel-dev_1.0.5-1woody2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/libcamel-dev_ 1.0.5-1woody2_s390.deb -
Debian libcamel-dev_1.0.5-1woody2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/libcamel-dev_ 1.0.5-1woody2_sparc.deb -
Debian libcamel0_1.0.5-1woody2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/libcamel0_1.0 .5-1woody2_alpha.deb -
Debian libcamel0_1.0.5-1woody2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/libcamel0_1.0 .5-1woody2_arm.deb -
Debian libcamel0_1.0.5-1woody2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/libcamel0_1.0 .5-1woody2_i386.deb -
Debian libcamel0_1.0.5-1woody2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/libcamel0_1.0 .5-1woody2_ia64.deb -
Debian libcamel0_1.0.5-1woody2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/libcamel0_1.0 .5-1woody2_m68k.deb -
Debian libcamel0_1.0.5-1woody2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/libcamel0_1.0 .5-1woody2_powerpc.deb -
Debian libcamel0_1.0.5-1woody2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/libcamel0_1.0 .5-1woody2_s390.deb -
Debian libcamel0_1.0.5-1woody2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/evolution/libcamel0_1.0 .5-1woody2_sparc.deb
Mandriva Linux Mandrake 10.0
-
Mandrake evolution-1.4.6-5.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake evolution-devel-1.4.6-5.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake evolution-pilot-1.4.6-5.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php
Mandriva Linux Mandrake 10.0 AMD64
-
Mandrake evolution-1.4.6-5.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake evolution-devel-1.4.6-5.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake evolution-pilot-1.4.6-5.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php
Mandriva Linux Mandrake 10.1
-
Mandrake evolution-2.0.3-1.2.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake evolution-devel-2.0.3-1.2.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake evolution-pilot-2.0.3-1.2.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php
Mandriva Linux Mandrake 10.1 x86_64
-
Mandrake evolution-2.0.3-1.2.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake evolution-devel-2.0.3-1.2.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake evolution-pilot-2.0.3-1.2.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php
Novell Evolution 2.0.2
-
Ubuntu evolution-dev_2.0.2-0ubuntu2.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/e/evolution/evolution-dev_ 2.0.2-0ubuntu2.1_amd64.deb -
Ubuntu evolution-dev_2.0.2-0ubuntu2.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/e/evolution/evolution-dev_ 2.0.2-0ubuntu2.1_i386.deb -
Ubuntu evolution-dev_2.0.2-0ubuntu2.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/e/evolution/evolution-dev_ 2.0.2-0ubuntu2.1_powerpc.deb -
Ubuntu evolution_2.0.2-0ubuntu2.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/e/evolution/evolution_2.0. 2-0ubuntu2.1_amd64.deb -
Ubuntu evolution_2.0.2-0ubuntu2.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/e/evolution/evolution_2.0. 2-0ubuntu2.1_i386.deb -
Ubuntu evolution_2.0.2-0ubuntu2.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/e/evolution/evolution_2.0. 2-0ubuntu2.1_powerpc.deb -
Ubuntu evolution1.5_2.0.2-0ubuntu2.1_all.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/e/evolution/evolution1.5_2 .0.2-0ubuntu2.1_all.deb
MandrakeSoft Corporate Server 3.0 x86_64
-
Mandrake evolution-1.4.6-5.1.C30mdk.x86_64.rpm
Mandrake Corporate Server 3.0/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake evolution-devel-1.4.6-5.1.C30mdk.x86_64.rpm
Mandrake Corporate Server 3.0/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake evolution-pilot-1.4.6-5.1.C30mdk.x86_64.rpm
Mandrake Corporate Server 3.0/x86_64
http://www.mandrakesecure.net/en/ftp.php
MandrakeSoft Corporate Server 3.0
-
Mandrake evolution-1.4.6-5.1.C30mdk.i586.rpm
Mandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake evolution-devel-1.4.6-5.1.C30mdk.i586.rpm
Mandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake evolution-pilot-1.4.6-5.1.C30mdk.i586.rpm
Mandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php
SuSE Linux 8.1
-
SuSE evolution-1.0.8-223.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/evolution-1.0.8-2 23.i586.rpm -
SuSE evolution-devel-1.0.8-223.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/evolution-devel-1 .0.8-223.i586.rpm
S.u.S.E. Linux Personal 8.2
-
SuSE evolution-1.2.3-161.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/evolution-1.2.3-1 61.i586.rpm -
SuSE evolution-devel-1.2.3-161.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/evolution-devel-1 .2.3-161.i586.rpm
S.u.S.E. Linux Personal 9.0
-
SuSE evolution-1.4.4-108.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/evolution-1.4.4-1 08.i586.rpm -
SuSE evolution-devel-1.4.4-108.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/evolution-devel-1 .4.4-108.i586.rpm
S.u.S.E. Linux Personal 9.0 x86_64
-
SuSE evolution-1.4.4-108.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/evolution-1.4 .4-108.x86_64.rpm -
SuSE evolution-devel-1.4.4-108.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/evolution-dev el-1.4.4-108.x86_64.rpm
S.u.S.E. Linux Personal 9.1
-
SuSE evolution-1.4.6-18.4.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/evolution-1.4.6-1 8.4.i586.rpm -
SuSE evolution-1.4.6-18.4.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/evolution-1.4 .6-18.4.x86_64.rpm -
SuSE evolution-devel-1.4.6-18.4.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/evolution-devel-1 .4.6-18.4.i586.rpm -
SuSE evolution-devel-1.4.6-18.4.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/evolution-dev el-1.4.6-18.4.x86_64.rpm
S.u.S.E. Linux Personal 9.2
-
SuSE evolution-2.0.1-6.4.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/evolution-2.0.1-6 .4.i586.rpm -
SuSE evolution-2.0.1-6.4.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/evolution-2.0 .1-6.4.x86_64.rpm -
SuSE evolution-devel-2.0.1-6.4.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/evolution-devel-2 .0.1-6.4.i586.rpm -
SuSE evolution-devel-2.0.1-6.4.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/evolution-dev el-2.0.1-6.4.x86_64.rpm -
SuSE evolution-pilot-2.0.1-6.4.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/evolution-pilot-2 .0.1-6.4.i586.rpm -
SuSE evolution-pilot-2.0.1-6.4.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/evolution-pil ot-2.0.1-6.4.x86_64.rpm
References
Novell Evolution Camel-Lock-Helper Application Remote Integer Overflow Vulnerability
References:
References: