Evolution Mailer Malformed MIME Header Denial Of Service Vulnerability
BID:4715
Info
Evolution Mailer Malformed MIME Header Denial Of Service Vulnerability
| Bugtraq ID: | 4715 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2002 12:00AM |
| Updated: | May 06 2002 12:00AM |
| Credit: | This issue was originally publicized in a Red Hat advisory. |
| Vulnerable: |
Ximian Evolution 1.0.4 Ximian Evolution 1.0.3 |
| Not Vulnerable: |
Ximian Evolution 1.0.5 |
Discussion
Evolution Mailer Malformed MIME Header Denial Of Service Vulnerability
Evolution is personal and workgroup information management software for Linux and Unix based systems. It provides a mailer, calendaring, and a contact manager.
Evolution is prone to a denial of service condition. This condition occurs when the Evolution mailer attempts to parse an e-mail with a malformed MIME header.
Evolution is personal and workgroup information management software for Linux and Unix based systems. It provides a mailer, calendaring, and a contact manager.
Evolution is prone to a denial of service condition. This condition occurs when the Evolution mailer attempts to parse an e-mail with a malformed MIME header.
Exploit / POC
Evolution Mailer Malformed MIME Header Denial Of Service Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Evolution Mailer Malformed MIME Header Denial Of Service Vulnerability
Solution:
Upgraded packages have been made available for Conectiva Linux 8.0. Conectiva Linux 7.0 also ships with Evolution, however, the vendor has announced that fixed packages will not be made available for this version of the distribution.
Additional upgrades are available.
Ximian Evolution 1.0.3
Ximian Evolution 1.0.4
Solution:
Upgraded packages have been made available for Conectiva Linux 8.0. Conectiva Linux 7.0 also ships with Evolution, however, the vendor has announced that fixed packages will not be made available for this version of the distribution.
Additional upgrades are available.
Ximian Evolution 1.0.3
-
Conectiva evolution-1.0.3-6U8_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/evolution-1.0.3-6U8_1cl.i38 6.rpm -
Conectiva evolution-1.0.3-6U8_1cl.src.rpm
Source RPM.
ftp://atualizacoes.conectiva.com.br/8/SRPMS/evolution-1.0.3-6U8_1cl.sr c.rpm -
Conectiva evolution-devel-1.0.3-6U8_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/evolution-devel-1.0.3-6U8_1 cl.i386.rpm -
Conectiva evolution-devel-static-1.0.3-6U8_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/evolution-devel-static-1.0. 3-6U8_1cl.i386.rpm -
Red Hat evolution-1.0.3-6.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/evolution-1.0.3-6.i386.rpm -
Red Hat evolution-1.0.3-6.src.rpm
Source RPM.
ftp://updates.redhat.com/7.3/en/os/SRPMS/evolution-1.0.3-6.src.rpm -
Ximian Evolution 1.05
http://www.ximian.com/products/ximian_evolution/download.html
Ximian Evolution 1.0.4
-
Ximian Evolution 1.05
http://www.ximian.com/products/ximian_evolution/download.html
References
Evolution Mailer Malformed MIME Header Denial Of Service Vulnerability
References:
References:
- Ximian Evolution Product Page (Ximian)