<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>170879</bug_id>
          
          <creation_ts>2007-03-14 14:05 0000</creation_ts>
          <short_desc>mail-client/evolution format string error (CVE-2007-1002)</short_desc>
          <delta_ts>2007-06-06 21:00:02 0000</delta_ts>
          
          
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>A2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>171107</dependson>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>gnome-office@gentoo.org</cc>
    
    <cc>liquidx@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-14 14:05:21 0000</bug_when>
            <thetext>A format string error in the &quot;write_html()&quot; function in calendar/gui/e-
cal-component-memo-preview.c when displaying a memo&apos;s categories can
potentially be exploited to execute arbitrary code via a specially
crafted shared memo containing format specifiers.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-14 14:06:48 0000</bug_when>
            <thetext>Btw please credit Ulf Härnhammar,Secunia.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-14 14:08:11 0000</bug_when>
            <thetext>Created an attachment (id=113257)
evo.diff

Patch by Harish Krishnaswamy, SUSE</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-03-15 21:15:16 0000</bug_when>
            <thetext>Thanks for the report, but if we CC the maintainer this will certainly be better :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-25 06:54:14 0000</bug_when>
            <thetext>*** Bug 171679 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2007-04-01 18:07:13 0000</bug_when>
            <thetext>Thank you for report Sune. But I have a question. Where did you get the patch from? Looking in upstream CVS I found the following commit to fix this issue:

http://svn.gnome.org/viewcvs/evolution/branches/gnome-2-18/calendar/gui/e-cal-component-memo-preview.c?r1=33312&amp;r2=33343

Also ubuntu patch which I got from http://secunia.com/advisories/24651 has the same fix.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2007-04-22 09:50:31 0000</bug_when>
            <thetext>This is fixed in &gt;=evolution-2.8.3-r2 which should be stabilized together with gnome-2.16.3.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>leio@gentoo.org</who>
            <bug_when>2007-06-02 03:08:32 0000</bug_when>
            <thetext>evolution-2.8.3-r2 is stable on all supported arches now.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-06-06 21:00:02 0000</bug_when>
            <thetext>GLSA 200706-02, thanks verybody</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>113257</attachid>
            <date>2007-03-14 14:08 0000</date>
            <desc>evo.diff</desc>
            <filename>evo.diff</filename>
            <type>text/plain</type>
            <data encoding="base64">SW5kZXg6IGNhbGVuZGFyL2d1aS9lLWNhbC1jb21wb25lbnQtbWVtby1wcmV2aWV3LmMKPT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PQotLS0gY2FsZW5kYXIvZ3VpL2UtY2FsLWNvbXBvbmVudC1tZW1vLXByZXZpZXcuYwkocmV2
aXNpb24gMzMyODEpCisrKyBjYWxlbmRhci9ndWkvZS1jYWwtY29tcG9uZW50LW1lbW8tcHJldmll
dy5jCSh3b3JraW5nIGNvcHkpCkBAIC0xMzgsNyArMTM4LDYgQEAKIAlFQ2FsQ29tcG9uZW50RGF0
ZVRpbWUgZHQ7CiAJZ2NoYXIgKnN0cjsKIAlHU0xpc3QgKmw7Ci0JZ2Jvb2xlYW4gb25lX2FkZGVk
ID0gRkFMU0U7CiAKIAlnX3JldHVybl9pZl9mYWlsIChFX0lTX0NBTF9DT01QT05FTlQgKGNvbXAp
KTsKIApAQCAtMTU4LDkgKzE1Nyw3IEBACiAJZV9jYWxfY29tcG9uZW50X2dldF9jYXRlZ29yaWVz
X2xpc3QgKGNvbXAsICZsKTsKIAlpZiAobCkgewogCQlHU0xpc3QgKm5vZGU7Ci0JCUdTdHJpbmcg
KnN0cmluZyA9IGdfc3RyaW5nX25ldyAoTlVMTCk7CiAJCQotCQkKIAkJZ3RrX2h0bWxfc3RyZWFt
X3ByaW50ZihzdHJlYW0sICI8SDM+Q2F0ZWdvcmllczogIik7CiAKIAkJZm9yIChub2RlID0gbDsg
bm9kZSAhPSBOVUxMOyBub2RlID0gbm9kZS0+bmV4dCkgewpAQCAtMTcyLDIzICsxNjksMTEgQEAK
IAkJCQlndGtfaHRtbF9zdHJlYW1fcHJpbnRmIChzdHJlYW0sICI8SU1HIEFMVD1cIiVzXCIgU1JD
PVwiJXNcIj4iLAogCQkJCQkJCShjb25zdCBjaGFyICopIG5vZGUtPmRhdGEsIGljb25fZmlsZV91
cmkpOwogCQkJCWdfZnJlZSAoaWNvbl9maWxlX3VyaSk7Ci0JCQkJb25lX2FkZGVkID0gVFJVRTsK
IAkJCX0KLQkJCWVsc2V7Ci0JCQkJaWYob25lX2FkZGVkID09IEZBTFNFKXsKLQkJCQkJZ19zdHJp
bmdfYXBwZW5kX3ByaW50ZiAoc3RyaW5nLCAiJXMiLCAoY29uc3QgY2hhciAqKSBub2RlLT5kYXRh
KTsKLQkJCQkJb25lX2FkZGVkID0gVFJVRTsKLQkJCQl9Ci0JCQkJZWxzZXsKLQkJCQkJZ19zdHJp
bmdfYXBwZW5kX3ByaW50ZiAoc3RyaW5nLCAiLCAlcyIsIChjb25zdCBjaGFyICopIG5vZGUtPmRh
dGEpOwotCQkJCX0KLQkJCX0KKwkJCWVsc2UKKwkJCQlndGtfaHRtbF9zdHJlYW1fcHJpbnRmIChz
dHJlYW0sICIlcyAiLCAoY29uc3QgY2hhciAqKSBub2RlLT5kYXRhKTsKIAkJfQogCQkKLQkJZ3Rr
X2h0bWxfc3RyZWFtX3ByaW50ZihzdHJlYW0sIHN0cmluZy0+c3RyKTsKLQotCQlnX3N0cmluZ19m
cmVlIChzdHJpbmcsIFRSVUUpOwotCQogCQlndGtfaHRtbF9zdHJlYW1fcHJpbnRmKHN0cmVhbSwg
IjwvSDM+Iik7CiAKIAkJZV9jYWxfY29tcG9uZW50X2ZyZWVfY2F0ZWdvcmllc19saXN0IChsKTsK
</data>        

          </attachment>
    </bug>

</bugzilla>