Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Gnome Evolution Format String Vulnerability

Gnome Evolution is prone to a format-string vulnerability.

This issue presents itself because the application fails to properly sanitize user-supplied input before passing it as the format specifier in a shared memo.

A successful attack may crash the application or possibly lead to arbitrary code execution. This may facilitate unauthorized access or privilege escalation in the context of the user running the application.

Gnome Evolution version 2.8.2.1 is vulnerable to this issue; other versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus