Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index.

Subscriptions

Vendors Products
Evolution Subscribe
Enterprise Linux Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-1321-1 New evolution-data-server packages fix arbitrary code execution
Debian DSA Debian DSA DSA-1325-1 New evolution packages fix arbitrary code execution
EUVD EUVD EUVD-2007-3247 Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index.
Ubuntu USN Ubuntu USN USN-475-1 evolution-data-server vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc cve-icon cve-icon
http://bugzilla.gnome.org/show_bug.cgi?id=447414 cve-icon cve-icon
http://mail.gnome.org/archives/evolution-hackers/2007-June/msg00064.html cve-icon cve-icon
http://osvdb.org/37489 cve-icon cve-icon
http://secunia.com/advisories/25765 cve-icon cve-icon
http://secunia.com/advisories/25766 cve-icon cve-icon
http://secunia.com/advisories/25774 cve-icon cve-icon
http://secunia.com/advisories/25777 cve-icon cve-icon
http://secunia.com/advisories/25793 cve-icon cve-icon
http://secunia.com/advisories/25798 cve-icon cve-icon
http://secunia.com/advisories/25843 cve-icon cve-icon
http://secunia.com/advisories/25880 cve-icon cve-icon
http://secunia.com/advisories/25894 cve-icon cve-icon
http://secunia.com/advisories/25906 cve-icon cve-icon
http://secunia.com/advisories/25958 cve-icon cve-icon
http://secunia.com/advisories/26083 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200711-04.xml cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1321 cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1325 cve-icon cve-icon
http://www.gentoo.org/security/en/glsa/glsa-200707-03.xml cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:136 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_14_sr.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_42_evolution.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0509.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0510.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/471455/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/24567 cve-icon cve-icon
http://www.securitytracker.com/id?1018284 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-475-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2282 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/34964 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-3257 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11724 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-3257 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T14:14:11.504Z

Reserved: 2007-06-19T00:00:00.000Z

Link: CVE-2007-3257

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2007-06-19T16:30:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2007-3257

cve-icon Redhat

Severity : Important

Publid Date: 2007-06-14T00:00:00Z

Links: CVE-2007-3257 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses