|
|
Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2005:141: evolution Vulnerability Scan
Vulnerability Scan Summary Check for the version of the evolution package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2005:141 (evolution).
Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow
remote attackers to cause a denial of service (crash) and possibly execute
arbitrary code via (1) full vCard data, (2) contact data from remote LDAP
servers, or (3) task list data from remote servers. (CVE-2005-2549)
A format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote
attackers to cause a denial of service (crash) and possibly execute arbitrary
code via the calendar entries such as task lists, which are not properly
handled when the user selects the Calendars tab. (CVE-2005-2550)
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:141
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|