USN-583-1: Evolution vulnerability
5 March 2008
Evolution vulnerability
Releases
Packages
Details
Ulf Harnhammar discovered that Evolution did not correctly handle format
strings when processing encrypted emails. A remote attacker could exploit
this by sending a specially crafted email, resulting in arbitrary code
execution.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 7.10
Ubuntu 7.04
Ubuntu 6.10
Ubuntu 6.06
After a standard system upgrade you need to restart Evolution to effect
the necessary changes.