CVE-2005-0806
published 2005-05-02CVE-2005-0806: Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in…
PriorityP410medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.66%
74.0th percentile
Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | evolution | < evolution 2.0.4-2 (bookworm) | evolution 2.0.4-2 (bookworm) |
| gnome | evolution | >= 0 < 2.0.4-2 | 2.0.4-2 |
| gnome | evolution | >= 0 < 2.0.4-2 | 2.0.4-2 |
| gnome | evolution | >= 0 < 2.0.4-2 | 2.0.4-2 |
| gnome | evolution | >= 0 < 2.0.4-2 | 2.0.4-2 |
| ximian | evolution | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f8c7-gvwp-r93h: Evolution 2
ghsa_unreviewed·2022-05-01
CVE-2005-0806 [MEDIUM] GHSA-f8c7-gvwp-r93h: Evolution 2
Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames.
OSV
CVE-2005-0806: Evolution 2
osv·2005-05-02·CVSS 5.0
CVE-2005-0806 [MEDIUM] CVE-2005-0806: Evolution 2
Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames.
Ubuntu
Evolution vulnerabilities
vendor_ubuntu·2005-08-11
CVE-2005-0806 Evolution vulnerabilities
Title: Evolution vulnerabilities
Summary: Evolution vulnerabilities
Ulf Harnhammar disovered several format string vulnerabilities in
Evolution. By tricking an user into viewing a specially crafted vCard
attached to an email, specially crafted contact data from an LDAP
server, specially crafted task lists from remote servers, or saving
Calendar entries with this malicious task list data, it was possible
for an attacker to execute arbitrary code with the privileges of the
user running Evolution.
In addition, this update fixes a Denial of Service vulnerability in
the mail attachment parser. This could be exploited to crash Evolution
by tricking an user into opening a malicious email with a specially
crafted attachment file name. This does only affect the Ubuntu 4.10
version, the Evolution
Red Hat
security flaw
vendor_redhat·2005-03-20·CVSS 5.0
CVE-2005-0806 [MEDIUM] security flaw
security flaw
Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames.
Debian
CVE-2005-0806: evolution - Evolution 2.0.3 allows remote attackers to cause a denial of service (applicatio...
vendor_debian·2005·CVSS 5.0
CVE-2005-0806 [MEDIUM] CVE-2005-0806: evolution - Evolution 2.0.3 allows remote attackers to cause a denial of service (applicatio...
Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames.
Scope: local
bookworm: resolved (fixed in 2.0.4-2)
bullseye: resolved (fixed in 2.0.4-2)
forky: resolved (fixed in 2.0.4-2)
sid: resolved (fixed in 2.0.4-2)
trixie: resolved (fixed in 2.0.4-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-0806 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2005-0806 [MEDIUM] CVE-2005-0806 security flaw
CVE-2005-0806 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames.
Bugzilla
CAN-2005-0806 DoS from mail message
bugzilla·2005-04-19
[MEDIUM] CAN-2005-0806 DoS from mail message
CAN-2005-0806 DoS from mail message
+++ This bug was initially created as a clone of Bug #155377 +++
Email from bressers:
CAN-2005-0806
source=cve
Evolution 2.0.3 allows remote attackers to cause a denial of
service (application crash) via crafted messages, possibly
involving charsets in attachment filenames.
http://bugzilla.ximian.com/show_bug.cgi?id=72609
Discussion:
Fix ready to build; awaiting notting pushing mozilla-1.7.7 into buildroot for FC3
---
(or someone else for that matter)
---
built into dist-fc3-updates-candidate; waiting for it to be signed and pushed
---
Pushed and announced; closing this bug.
Bugzilla
CAN-2005-0806 DoS from mail message
bugzilla·2005-04-19
[MEDIUM] CAN-2005-0806 DoS from mail message
CAN-2005-0806 DoS from mail message
Email from bressers:
CAN-2005-0806
source=cve
Evolution 2.0.3 allows remote attackers to cause a denial of
service (application crash) via crafted messages, possibly
involving charsets in attachment filenames.
http://bugzilla.ximian.com/show_bug.cgi?id=72609
Discussion:
built; will be part of RHSA-2005:397
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2005-397.html
http://bugzilla.ximian.com/show_bug.cgi?id=72609http://www.mandriva.com/security/advisories?name=MDKSA-2005:059http://www.redhat.com/support/errata/RHSA-2005-397.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10532https://usn.ubuntu.com/166-1/http://bugzilla.ximian.com/show_bug.cgi?id=72609http://www.mandriva.com/security/advisories?name=MDKSA-2005:059http://www.redhat.com/support/errata/RHSA-2005-397.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10532https://usn.ubuntu.com/166-1/
2005-05-02
Published