USN-583-1: Evolution vulnerability
===========================================================
Ubuntu Security Notice USN-583-1 March 05, 2008
evolution vulnerability
CVE-2008-0072
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
evolution 2.6.1-0ubuntu7.2
Ubuntu 6.10:
evolution 2.8.1-0ubuntu4.2
Ubuntu 7.04:
evolution 2.10.1-0ubuntu2.1
Ubuntu 7.10:
evolution 2.12.1-0ubuntu1.1
After a standard system upgrade you need to restart Evolution to effect
the necessary changes.
Details follow:
Ulf Harnhammar discovered that Evolution did not correctly handle format
strings when processing encrypted emails. A remote attacker could exploit
this by sending a specially crafted email, resulting in arbitrary code
execution.



