Home | Docs | Forums | Lists | Bugs | Planet | Store | GMN | Get Gentoo!
Not eligible to see or edit group visibility for this bug.
View Bug Activity | Format For Printing | XML | Clone This Bug
Secunia Research has discovered a vulnerability in Evolution, which potentially can be exploited by malicious people to compromise a vulnerable system. A format string error in the "write_html()" function in calendar/gui/e-cal-component-memo-preview.c when displaying a memo's categories can potentially be exploited to execute arbitrary code via a specially crafted shared memo containing format specifiers. Successful exploitation requires that the user opens a shared memo in their mailbox, clicks on "Accept", and views the memo under the "Memo" tab. NOTE: The categories are not displayed in the mailbox view of a shared memo. The vulnerability is confirmed in version 2.8.2.1. Other versions may also be affected.
*** This bug has been marked as a duplicate of bug 170879 ***