Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1) addressbook/libebook/e-vcard.c in evc or (2) camel/camel-mime-utils.c in libcamel.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade evolution-data-server | Jul 30, 2024 | Mar 14, 2009 |
| Oracle_linux | — | Upgrade evolution-data-serverUpgrade evolution-data-server-docUpgrade evolution-data-server-devel | Oct 16, 2024 | Mar 14, 2009 |
| Suse | — | Upgrade evolution-data-server-x86Upgrade evolution-data-server-langUpgrade evolution-data-server-32bitUpgrade evolution-data-server | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libcamel1.2-8Upgrade libcamel1.2-10Upgrade libebook1.2-5Upgrade libebook1.2-9 | Nov 8, 2024 | Mar 14, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub