Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade evolution | Jul 30, 2024 | Jan 24, 2005 |
| Freebsd | — | Upgrade evolution | Dec 10, 2025 | Jan 25, 2005 |
| Gentoo Linux | — | Upgrade mail-client/evolution. | Oct 30, 2017 | Jan 24, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub