CVE-2008-1108
published 2008-06-04CVE-2008-1108: Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string…
PriorityP340high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
5.69%
92.1th percentile
Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attachment.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | evolution | < evolution 2.22.2-1.1 (bookworm) | evolution 2.22.2-1.1 (bookworm) |
| gnome | evolution | — | — |
| gnome | evolution | >= 0 < 2.22.2-1.1 | 2.22.2-1.1 |
| gnome | evolution | >= 0 < 2.22.2-1.1 | 2.22.2-1.1 |
| gnome | evolution | >= 0 < 2.22.2-1.1 | 2.22.2-1.1 |
| gnome | evolution | >= 0 < 2.22.2-1.1 | 2.22.2-1.1 |
CVSS provenance
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv7.6HIGH
vendor_debian7.6LOW
vendor_redhat7.6HIGH
vendor_ubuntu7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-839c-2pvm-jv7q: Buffer overflow in Evolution 2
ghsa_unreviewed·2022-05-01
CVE-2008-1108 [HIGH] CWE-119 GHSA-839c-2pvm-jv7q: Buffer overflow in Evolution 2
Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attachment.
OSV
CVE-2008-1108: Buffer overflow in Evolution 2
osv·2008-06-04·CVSS 7.6
CVE-2008-1108 [HIGH] CVE-2008-1108: Buffer overflow in Evolution 2
Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attachment.
Ubuntu
Evolution vulnerabilities
vendor_ubuntu·2008-06-06·CVSS 7.6
CVE-2008-1108 [HIGH] Evolution vulnerabilities
Title: Evolution vulnerabilities
Summary: Evolution vulnerabilities
Alin Rad Pop of Secunia Research discovered that Evolution did not
properly validate timezone data when processing iCalendar attachments.
If a user disabled the ITip Formatter plugin and viewed a crafted
iCalendar attachment, an attacker could cause a denial of service or
possibly execute code with user privileges. Note that the ITip
Formatter plugin is enabled by default in Ubuntu. (CVE-2008-1108)
Alin Rad Pop of Secunia Research discovered that Evolution did not
properly validate the DESCRIPTION field when processing iCalendar
attachments. If a user were tricked into accepting a crafted
iCalendar attachment and replied to it from the calendar window, an
attacker code cause a denial of service or execute code with user
Red Hat
evolution: iCalendar buffer overflow via large timezone specification
vendor_redhat·2008-06-04·CVSS 7.6
CVE-2008-1108 [HIGH] CWE-119 evolution: iCalendar buffer overflow via large timezone specification
evolution: iCalendar buffer overflow via large timezone specification
Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attachment.
Debian
CVE-2008-1108: evolution - Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled,...
vendor_debian·2008·CVSS 7.6
CVE-2008-1108 [HIGH] CVE-2008-1108: evolution - Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled,...
Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attachment.
Scope: local
bookworm: resolved (fixed in 2.22.2-1.1)
bullseye: resolved (fixed in 2.22.2-1.1)
forky: resolved (fixed in 2.22.2-1.1)
sid: resolved (fixed in 2.22.2-1.1)
trixie: resolved (fixed in 2.22.2-1.1)
No detection rules found.
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00003.htmlhttp://secunia.com/advisories/30298http://secunia.com/advisories/30527http://secunia.com/advisories/30536http://secunia.com/advisories/30564http://secunia.com/advisories/30571http://secunia.com/advisories/30702http://secunia.com/advisories/30716http://secunia.com/secunia_research/2008-22/advisory/http://security.gentoo.org/glsa/glsa-200806-06.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:111http://www.redhat.com/support/errata/RHSA-2008-0514.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0515.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0516.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0517.htmlhttp://www.securityfocus.com/bid/29527http://www.securitytracker.com/id?1020169http://www.ubuntu.com/usn/usn-615-1http://www.vupen.com/english/advisories/2008/1732/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/42824https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10471https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00157.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-June/msg00178.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-June/msg00179.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-06/msg00003.htmlhttp://secunia.com/advisories/30298http://secunia.com/advisories/30527http://secunia.com/advisories/30536http://secunia.com/advisories/30564http://secunia.com/advisories/30571http://secunia.com/advisories/30702http://secunia.com/advisories/30716http://secunia.com/secunia_research/2008-22/advisory/http://security.gentoo.org/glsa/glsa-200806-06.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:111http://www.redhat.com/support/errata/RHSA-2008-0514.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0515.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0516.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0517.htmlhttp://www.securityfocus.com/bid/29527http://www.securitytracker.com/id?1020169http://www.ubuntu.com/usn/usn-615-1http://www.vupen.com/english/advisories/2008/1732/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/42824https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10471https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00157.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-June/msg00178.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-June/msg00179.html
2008-06-04
Published