Description: | Description:
The remote host is missing an update to evolution announced via advisory FEDORA-2008-5018.
Update Information:
Fix two buffer overflows in iCalendar .ics file fromat support discovered and reported by Alin Rad Pop of the Secunia Research: CVE-2008-1108, CVE-2008-1109, SA30298 See referenced bugzilla bugs or Secunia advisories for further details: http://secunia.com/advisories/30298 http://secunia.com/secunia_research/2008-22/advisory/ http://secunia.com/secunia_research/2008-23/advisory/
ChangeLog:
* Wed Jun 4 2008 Matthew Barnes - 2.10.3-10.fc7 - Add patches for RH bug #449922 (buffer overflow vulnerabilities).
References:
[ 1 ] Bug #448541 - CVE-2008-1109 evolution: iCalendar buffer overflow via large description parameter https://bugzilla.redhat.com/show_bug.cgi?id=448541 [ 2 ] Bug #448540 - CVE-2008-1108 evolution: iCalendar buffer overflow via large timezone specification https://bugzilla.redhat.com/show_bug.cgi?id=448540
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update evolution' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2008-5018
Risk factor : Critical
CVSS Score: 9.3
|