vendor:
Evolution
by:
SecurityFocus
7.5
CVSS
HIGH
MIME Image/* Content-Type Validation Vulnerability
20
CWE
Product Name: Evolution
Affected Version From: Ximian Evolution 1.0.x
Affected Version To: Ximian Evolution 1.2.x
Patch Exists: Yes
Related CWE: N/A
CPE: a:ximian:evolution
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2003
Ximian Evolution MIME Image/* Content-Type Validation Vulnerability
Ximian Evolution does not properly validate MIME image/* Content-Type fields. If an email message contains an image/* Content-Type, any type of data can be embedded where the image information is expected. This can be used to embed HTML tags that will be rendered by GTKHtml, bypass policies, or invoke bonobo components to handle external content types.
Mitigation:
Ensure that Ximian Evolution is up to date with the latest security patches.