Synopsis: Important: evolution security update Issue date: 2008-06-04 CVE Names: CVE-2008-1108 CVE-2008-1109 A flaw was found in the way Evolution parsed iCalendar timezone attachment data. If the Itip Formatter plug-in was disabled and a user opened a mail with a carefully crafted iCalendar attachment, arbitrary code could be executed as the user running Evolution. (CVE-2008-1108) Note: the Itip Formatter plug-in, which allows calendar information (attachments with a MIME type of "text/calendar") to be displayed as part of the e-mail message, is enabled by default. A heap-based buffer overflow flaw was found in the way Evolution parsed iCalendar attachments with an overly long "DESCRIPTION" property string. If a user responded to a carefully crafted iCalendar attachment in a particular way, arbitrary code could be executed as the user running Evolution. (CVE-2008-1109). SL 5.x SRPMS: evolution-2.12.3-8.el5_2.2.src.rpm i386: evolution-2.12.3-8.el5_2.2.i386.rpm evolution-devel-2.12.3-8.el5_2.2.i386.rpm evolution-help-2.12.3-8.el5_2.2.i386.rpm x86_64: evolution-2.12.3-8.el5_2.2.i386.rpm evolution-2.12.3-8.el5_2.2.x86_64.rpm evolution-devel-2.12.3-8.el5_2.2.i386.rpm evolution-devel-2.12.3-8.el5_2.2.x86_64.rpm evolution-help-2.12.3-8.el5_2.2.x86_64.rpm -Connie Sieh -Troy Dawson