6.8
CVSSv2

CVE-2007-1002

Published: 21/03/2007 Updated: 16/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in the write_html function in calendar/gui/e-cal-component-memo-preview.c in Evolution Shared Memo 2.8.2.1, and possibly earlier versions, allows user-assisted remote malicious users to execute arbitrary code via format specifiers in the categories of a crafted shared memo.

Vulnerable Product Search on Vulmon Subscribe to Product

evolution shared memo 2.8.2.1

Vendor Advisories

Ulf Harnhammar of Secunia Research discovered that Evolution did not correctly handle format strings when displaying shared memos If a remote attacker tricked a user into viewing a specially crafted shared memo, they could execute arbitrary code with user privileges ...