Synopsis: Important: evolution28 security update Issue date: 2008-06-04 CVE Names: CVE-2008-1108 CVE-2008-1109 A flaw was found in the way Evolution parsed iCalendar timezone attachment data. If the Itip Formatter plug-in was disabled and a user opened a mail with a carefully crafted iCalendar attachment, arbitrary code could be executed as the user running Evolution. (CVE-2008-1108) Note: the Itip Formatter plug-in, which allows calendar information (attachments with a MIME type of "text/calendar") to be displayed as part of the e-mail message, is enabled by default. A heap-based buffer overflow flaw was found in the way Evolution parsed iCalendar attachments with an overly long "DESCRIPTION" property string. If a user responded to a carefully crafted iCalendar attachment in a particular way, arbitrary code could be executed as the user running Evolution. (CVE-2008-1109). SL 4.x SRPMS: evolution28-2.8.0-53.el4_6.3.src.rpm i386: evolution28-2.8.0-53.el4_6.3.i386.rpm evolution28-devel-2.8.0-53.el4_6.3.i386.rpm x86_64: evolution28-2.8.0-53.el4_6.3.x86_64.rpm evolution28-devel-2.8.0-53.el4_6.3.x86_64.rpm -Connie Sieh -Troy Dawson