Oval Definition:oval:com.redhat.rhsa:def:20050397
Revision Date:2005-05-04Version:502
Title:RHSA-2005:397: evolution security update (Moderate)
Description:Evolution is a GNOME-based collection of personal information management (PIM) tools.

A bug was found in the way Evolution displays mail messages. It is possible that an attacker could create a specially crafted mail message that when opened by a victim causes Evolution to stop responding. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0806 to this issue.

A bug was also found in Evolution's helper program camel-lock-helper. This bug could allow a local attacker to gain root privileges if camel-lock-helper has been built to execute with elevated privileges. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0102 to this issue. On Red Hat Enterprise Linux, camel-lock-helper is not built to execute with elevated privileges by default. Please note however that if users have rebuilt Evolution from the source RPM, as the root user, camel-lock-helper may be given elevated privileges.

All users of evolution should upgrade to these updated packages, which include backported fixes to correct these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2005-0102
CVE-2005-0806
RHSA-2005:397-01
Platform(s):Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 4 is installed
  • AND Package Information
  • evolution is earlier than 0:2.0.2-16
  • AND evolution is signed with Red Hat master key
  • OR
  • evolution-devel is earlier than 0:2.0.2-16
  • AND evolution-devel is signed with Red Hat master key
  • BACK