FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-0102

This CVE name corresponds to:

Entered Topic
2005-01-25 evolution -- arbitrary code execution vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-0102
Phase Assigned(20050118)

Description

Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.

References

Source Reference
CONECTIVA CLA-2005:925
DEBIAN DSA-673
GENTOO GLSA-200501-35
MANDRAKE MDKSA-2005:024
REDHAT RHSA-2005:238
REDHAT RHSA-2005:397
UBUNTU USN-69-1
BID 12354
OVAL oval:org.mitre.oval:def:9616
SECTRACK 1012981
SECUNIA 13830
XF evolution-camellockhelper-bo(19031)