CVE-2007-3257
published 2007-06-19CVE-2007-3257: Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE…
PriorityP335medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.12%
86.4th percentile
Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | evolution | < evolution 2.12.0-1 (bookworm) | evolution 2.12.0-1 (bookworm) |
| debian | evolution-data-server | < evolution 2.12.0-1 (bookworm) | evolution 2.12.0-1 (bookworm) |
| gnome | evolution | — | — |
| gnome | evolution | >= 0 < 2.12.0-1 | 2.12.0-1 |
| gnome | evolution | >= 0 < 2.12.0-1 | 2.12.0-1 |
| gnome | evolution | >= 0 < 2.12.0-1 | 2.12.0-1 |
| gnome | evolution | >= 0 < 2.12.0-1 | 2.12.0-1 |
| gnome | evolution-data-server | >= 0 < 1.10.2-2 | 1.10.2-2 |
| gnome | evolution-data-server | >= 0 < 1.10.2-2 | 1.10.2-2 |
| gnome | evolution-data-server | >= 0 < 1.10.2-2 | 1.10.2-2 |
| gnome | evolution-data-server | >= 0 < 1.10.2-2 | 1.10.2-2 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
evolution-data-server vulnerability
vendor_ubuntu·2007-06-21
CVE-2007-3257 evolution-data-server vulnerability
Title: evolution-data-server vulnerability
Summary: evolution-data-server vulnerability
Philip Van Hoof discovered that the IMAP client in Evolution did not
correctly verify the SEQUENCE value. A malicious or spoofed server
could exploit this to execute arbitrary code with user privileges.
Instructions: After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Red Hat
evolution malicious server arbitrary code execution
vendor_redhat·2007-06-14·CVSS 6.8
CVE-2007-3257 [MEDIUM] evolution malicious server arbitrary code execution
evolution malicious server arbitrary code execution
Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index.
Debian
CVE-2007-3257: evolution - Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1....
vendor_debian·2007·CVSS 6.8
CVE-2007-3257 [MEDIUM] CVE-2007-3257: evolution - Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1....
Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index.
Scope: local
bookworm: resolved (fixed in 2.12.0-1)
bullseye: resolved (fixed in 2.12.0-1)
forky: resolved (fixed in 2.12.0-1)
sid: resolved (fixed in 2.12.0-1)
trixie: resolved (fixed in 2.12.0-1)
GHSA
GHSA-6ggg-vv7h-7mm5: Camel (camel-imap-folder
ghsa_unreviewed·2022-05-03
CVE-2007-3257 [MEDIUM] GHSA-6ggg-vv7h-7mm5: Camel (camel-imap-folder
Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index.
OSV
CVE-2007-3257: Camel (camel-imap-folder
osv·2007-06-19·CVSS 6.8
CVE-2007-3257 [MEDIUM] CVE-2007-3257: Camel (camel-imap-folder
Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-3257 evolution malicious server arbitrary code execution
bugzilla·2007-06-14·CVSS 6.8
CVE-2007-3257 [MEDIUM] CVE-2007-3257 evolution malicious server arbitrary code execution
CVE-2007-3257 evolution malicious server arbitrary code execution
A bug was reported to the upstream BTS detailing a flaw in the way evolution
accepts IMAP server data. To quote the upstream bug:
The "SEQUENCE" value in the GData of the IMAP code (camel-imap-folder.c)
is converted from a string using strtol. This allows for negative values.
The imap_rescan uses this value as an int. It checks for !seq and
seq>summary.length. It doesn't check for seq < 0. Although seq is used as
the index of an array.
This means that a negative index number can be fed to the array lookup by
altering the output of an IMAP server.
I'm marking this as a blocker (very very serious) security bug as this is
remotely exploitable (I can put shell code in the UID field of the IMAP
code, and make it execute on t
Bugzilla
CVE-2007-3257 Evolution malicious server arbitrary code execution [FC5]
bugzilla·2007-06-14·CVSS 6.8
CVE-2007-3257 [MEDIUM] CVE-2007-3257 Evolution malicious server arbitrary code execution [FC5]
CVE-2007-3257 Evolution malicious server arbitrary code execution [FC5]
FC5 tracking bug: see blocks bug list for full details of the security issue(s).
Discussion:
Fixed in evolution-data-server-1.6.3-5.fc5.
Bugzilla
CVE-2007-3257 Evolution malicious server arbitrary code execution [F7]
bugzilla·2007-06-14·CVSS 6.8
CVE-2007-3257 [MEDIUM] CVE-2007-3257 Evolution malicious server arbitrary code execution [F7]
CVE-2007-3257 Evolution malicious server arbitrary code execution [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
Discussion:
Fixed in evolution-data-server-1.10.2-3.fc7.
---
evolution-data-server-1.10.2-3.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-3257 Evolution malicious server arbitrary code execution [FC6]
bugzilla·2007-06-14·CVSS 6.8
CVE-2007-3257 [MEDIUM] CVE-2007-3257 Evolution malicious server arbitrary code execution [FC6]
CVE-2007-3257 Evolution malicious server arbitrary code execution [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
Discussion:
Fixed in evolution-data-server-1.8.3-7.fc6.
ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.aschttp://bugzilla.gnome.org/show_bug.cgi?id=447414http://mail.gnome.org/archives/evolution-hackers/2007-June/msg00064.htmlhttp://osvdb.org/37489http://secunia.com/advisories/25765http://secunia.com/advisories/25766http://secunia.com/advisories/25774http://secunia.com/advisories/25777http://secunia.com/advisories/25793http://secunia.com/advisories/25798http://secunia.com/advisories/25843http://secunia.com/advisories/25880http://secunia.com/advisories/25894http://secunia.com/advisories/25906http://secunia.com/advisories/25958http://secunia.com/advisories/26083http://security.gentoo.org/glsa/glsa-200711-04.xmlhttp://www.debian.org/security/2007/dsa-1321http://www.debian.org/security/2007/dsa-1325http://www.gentoo.org/security/en/glsa/glsa-200707-03.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:136http://www.novell.com/linux/security/advisories/2007_14_sr.htmlhttp://www.novell.com/linux/security/advisories/2007_42_evolution.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0509.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0510.htmlhttp://www.securityfocus.com/archive/1/471455/100/0/threadedhttp://www.securityfocus.com/bid/24567http://www.securitytracker.com/id?1018284http://www.ubuntu.com/usn/usn-475-1http://www.vupen.com/english/advisories/2007/2282https://exchange.xforce.ibmcloud.com/vulnerabilities/34964https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11724ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.aschttp://bugzilla.gnome.org/show_bug.cgi?id=447414http://mail.gnome.org/archives/evolution-hackers/2007-June/msg00064.htmlhttp://osvdb.org/37489http://secunia.com/advisories/25765http://secunia.com/advisories/25766http://secunia.com/advisories/25774http://secunia.com/advisories/25777http://secunia.com/advisories/25793http://secunia.com/advisories/25798http://secunia.com/advisories/25843http://secunia.com/advisories/25880http://secunia.com/advisories/25894http://secunia.com/advisories/25906http://secunia.com/advisories/25958http://secunia.com/advisories/26083http://security.gentoo.org/glsa/glsa-200711-04.xmlhttp://www.debian.org/security/2007/dsa-1321http://www.debian.org/security/2007/dsa-1325http://www.gentoo.org/security/en/glsa/glsa-200707-03.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:136http://www.novell.com/linux/security/advisories/2007_14_sr.htmlhttp://www.novell.com/linux/security/advisories/2007_42_evolution.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0509.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0510.htmlhttp://www.securityfocus.com/archive/1/471455/100/0/threadedhttp://www.securityfocus.com/bid/24567http://www.securitytracker.com/id?1018284http://www.ubuntu.com/usn/usn-475-1http://www.vupen.com/english/advisories/2007/2282https://exchange.xforce.ibmcloud.com/vulnerabilities/34964https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11724
2007-06-19
Published