Vulnerability Name:

CVE-2009-0587 (CCN-49275)

Assigned:2009-03-12
Published:2009-03-12
Updated:2023-02-13
Summary:Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1) addressbook/libebook/e-vcard.c in evc or (2) camel/camel-mime-utils.c in libcamel.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
5.1 Medium (REDHAT CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
3.8 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-190
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2009-0587

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: Patch
secalert@redhat.com

Source: secalert@redhat.com
Type: Patch
secalert@redhat.com

Source: secalert@redhat.com
Type: Patch
secalert@redhat.com

Source: CCN
Type: Evolution Web page
Evolution

Source: CCN
Type: RHSA-2009-0354
Moderate: evolution-data-server security update

Source: CCN
Type: RHSA-2009-0355
Moderate: evolution and evolution-data-server security update

Source: CCN
Type: RHSA-2009-0358
Moderate: evolution security update

Source: CCN
Type: SA34334
Evolution Base64 Integer Overflow Vulnerabilities

Source: CCN
Type: SA34338
Red Hat update for evolution-data-server

Source: CCN
Type: SA34339
Red Hat update for evolution and evolution-data-server

Source: CCN
Type: SA34348
Red Hat update for evolution

Source: CCN
Type: SA34351
Ubuntu update for evolution

Source: CCN
Type: SA35357
Debian update for evolution-data-server

Source: CCN
Type: SA40541
Sun Solaris Evolution Base64 Integer Overflow Vulnerabilities

Source: CCN
Type: ASA-2009-085
evolution security update (RHSA-2009-0358)

Source: CCN
Type: ASA-2009-086
evolution-data-server security update (RHSA-2009-0354)

Source: CCN
Type: ASA-2009-087
evolution and evolution-data-server security update (RHSA-2009-0355)

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: DEBIAN
Type: DSA-1813
evolution-data-server -- Several vulnerabilities

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: oCERT Advisories #2008-015
glib and glib-predecessor heap overflows

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: OSVDB ID: 52702
Evolution Data Server evc addressbook/libebook/e-vcard.c Base64 String Handling Overflow

Source: CCN
Type: OSVDB ID: 52703
Evolution Data Server libcamel camel/camel-mime-utils.c Base64 String Handling Overflow

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: BID-34100
GNOME glib Base64 Encoding and Decoding Multiple Integer Overflow Vulnerabilities

Source: secalert@redhat.com
Type: Patch
secalert@redhat.com

Source: CCN
Type: USN-733-1
evolution-data-server vulnerability

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: XF
Type: UNKNOWN
evolution-evcbase64encodesimple-bo(49275)

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*
  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:*
  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:5::client_workstation:*:*:*:*:*
  • Configuration RedHat 9:
  • cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20090587
    V
    CVE-2009-0587
    2022-05-20
    oval:org.opensuse.security:def:32161
    P
    Security update for cpio (Important)
    2021-08-14
    oval:org.opensuse.security:def:29389
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:29353
    P
    Security update for gdm (Important)
    2021-04-28
    oval:org.opensuse.security:def:32254
    P
    Security update for openvswitch (Important)
    2021-02-12
    oval:org.opensuse.security:def:27932
    P
    Security update for GraphicsMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32764
    P
    pam_mount on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28616
    P
    Security update for xorg-x11-libXext
    2020-12-01
    oval:org.opensuse.security:def:32311
    P
    Security update for quagga (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28007
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33441
    P
    Security update for evolution-data-server
    2020-12-01
    oval:org.opensuse.security:def:28671
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:32554
    P
    libltdl7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28221
    P
    Security update for libsndfile (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31942
    P
    Security update for gnome-session (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32659
    P
    expat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28362
    P
    Security update for postgresql94 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32027
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:27931
    P
    Security update for GraphicsMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32720
    P
    libnetpbm10 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28567
    P
    Security update for krb5
    2020-12-01
    oval:org.opensuse.security:def:27943
    P
    Security update for GraphicsMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33402
    P
    Security update for salt (Important)
    2020-12-01
    oval:org.opensuse.security:def:28655
    P
    Security update for dhcpcd (Important)
    2020-12-01
    oval:org.opensuse.security:def:32398
    P
    Security update for unzip (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28137
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:31941
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:28715
    P
    Security update for java-1_7_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:32610
    P
    unrar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28278
    P
    Security update for mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31953
    P
    Security update for gstreamer-0_10-plugins-base (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32698
    P
    lcms on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28514
    P
    Security update for openssl1 (Important)
    2020-12-01
    oval:org.mitre.oval:def:28741
    P
    RHSA-2009:0354 -- evolution-data-server security update (Moderate)
    2015-08-17
    oval:org.mitre.oval:def:13169
    P
    USN-733-1 -- evolution-data-server vulnerability
    2014-06-30
    oval:org.mitre.oval:def:8011
    P
    DSA-1813 evolution-data-server -- Several vulnerabilities
    2014-06-23
    oval:org.mitre.oval:def:13406
    P
    DSA-1813-2 evolution-data-server -- Several vulnerabilities
    2014-06-23
    oval:org.mitre.oval:def:12702
    P
    DSA-1813-1 evolution-data-server -- Several vulnerabilities
    2014-06-23
    oval:org.mitre.oval:def:21826
    P
    ELSA-2009:0354: evolution-data-server security update (Moderate)
    2014-05-26
    oval:org.mitre.oval:def:11385
    V
    Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1) addressbook/libebook/e-vcard.c in evc or (2) camel/camel-mime-utils.c in libcamel.
    2013-04-29
    oval:org.debian:def:1813
    V
    Several vulnerabilities
    2009-06-08
    oval:com.redhat.rhsa:def:20090354
    P
    RHSA-2009:0354: evolution-data-server security update (Moderate)
    2009-03-16
    oval:com.redhat.rhsa:def:20090355
    P
    RHSA-2009:0355: evolution and evolution-data-server security update (Moderate)
    2009-03-16
    oval:com.redhat.rhsa:def:20090358
    P
    RHSA-2009:0358: evolution security update (Moderate)
    2009-03-16
    BACK