Title : Debian Security Update Fixes Evolution Multiple Command Execution Vulnerabilities VUPEN ID : VUPEN/ADV-2007-2392 CVE ID : CVE-2007-1002 - CVE-2007-3257
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-02
Technical Description
Two vulnerabilities have been identified in Debian, which could be exploited by remote attackers to execute arbitrary code. These issues are caused by errors in Evolution. For additional information, see : VUPEN/ADV-2007-1058 - VUPEN/ADV-2007-2282
Debian GNU/Linux sarge - Upgrade to evolution version 2.0.4-2sarge2
Debian GNU/Linux etch - Upgrade to evolution version 2.6.3-6etch1
Debian GNU/Linux sid - A fix will be available soon References