vendor:
Evolution Mail Client
by:
SecurityFocus
7.5
CVSS
HIGH
Memory Corruption
119
CWE
Product Name: Evolution Mail Client
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2003
Evolution Mail Client UUEncoded Content Memory Corruption Vulnerability
The Evolution mail client supports 'uuencoded' content and decodes it automatically when a message is initially parsed. A memory corruption error is present in the parsing component that can result in the client crashing when specially malformed content is decoded. The presence of such a message in an Evolution user's mailbox may result in a prolonged denial of service as the crashing of the GUI may prevent deletion of the message. The user will also not be able to read messages while the message is present in their mailbox.
Mitigation:
Users are advised to upgrade to the latest version of Evolution mail client.