Title : GNOME Evolution-data-server "imap_rescan()" Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2007-2282 CVE ID : CVE-2007-3257
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-06-21
Technical Description
A vulnerability has been identified in GNOME Evolution-data-server, which could be exploited by remote attackers to cause a denial of service or execute arbitrary code. This issue is caused by an error in the "imap_rescan()" [camel/providers/imap/camel-imap-folder.c] that does not validate the "SEQUENCE" value before being used as an array index, which could be exploited by attackers to compromise a vulnerable system by tricking a user into connecting to a specially crafted IMAP server.