Package : evolution-data-server
Vulnerability : programming error
Problem-Type : remote
Debian-specific: no
CVE ID : CVE-2007-3257
It was discovered that the IMAP code in the Evolution Data Server
performs insufficient sanitising of a value later used an array index,
which can lead to the execution of arbitrary code.
For the oldstable distribution (sarge) a different source package
is affected and will be fixed separately.
For the stable distribution (etch) this problem has been fixed in
version 1.6.3-5etch1.
For the unstable distribution (sid) this problem has been fixed in
version 1.10.2-2.
We recommend that you upgrade your evolution-data-server packages.
Upgrade Instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
These files will probably be moved into the stable distribution on
its next update.
---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFGfRaZXm3vHE4uyloRAm62AJ9d8sgAh339xR454ZatLIsw1bZbogCdEcAL
JUkR+27hmUuEkCEm8tDAAZM=
=dyCX
-----END PGP SIGNATURE----- Received on Sat Jun 23 12:37:23 2007
This archive was generated by hypermail 2.1.8
: Sat Jun 23 2007 - 12:40:03 EDT