CVE-2018-12422
published 2018-06-15CVE-2018-12422: addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow…
PriorityP348critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.84%
76.6th percentile
addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that is processed by the strcat function. NOTE: the software maintainer disputes this because "the code had computed the required string length first, and then allocated a large-enough buffer on the heap.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | evolution-data-server | < evolution-data-server 3.28.5-1 (bookworm) | evolution-data-server 3.28.5-1 (bookworm) |
| gnome | evolution | <= 3.29.2 | — |
| gnome | evolution-data-server | >= 0 < 3.28.5-1 | 3.28.5-1 |
| gnome | evolution-data-server | >= 0 < 3.28.5-1 | 3.28.5-1 |
| gnome | evolution-data-server | >= 0 < 3.28.5-1 | 3.28.5-1 |
| gnome | evolution-data-server | >= 0 < 3.28.5-1 | 3.28.5-1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rqw6-r9qq-6v6g: ** DISPUTED ** addressbook/backends/ldap/e-book-backend-ldap
ghsa_unreviewed·2022-05-14
CVE-2018-12422 [CRITICAL] CWE-119 GHSA-rqw6-r9qq-6v6g: ** DISPUTED ** addressbook/backends/ldap/e-book-backend-ldap
** DISPUTED ** addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that is processed by the strcat function. NOTE: the software maintainer disputes this because "the code had computed the required string length first, and then allocated a large-enough buffer on the heap."
OSV
CVE-2018-12422: addressbook/backends/ldap/e-book-backend-ldap
osv·2018-06-15·CVSS 9.8
CVE-2018-12422 [CRITICAL] CVE-2018-12422: addressbook/backends/ldap/e-book-backend-ldap
addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that is processed by the strcat function. NOTE: the software maintainer disputes this because "the code had computed the required string length first, and then allocated a large-enough buffer on the heap.
Red Hat
evolution-data-server: Unsafe use of strcat allows buffer overflow in addressbook/backends/ldap/e-book-backend-ldap.c
vendor_redhat·2018-05-16·CVSS 9.8
CVE-2018-12422 [CRITICAL] CWE-121 evolution-data-server: Unsafe use of strcat allows buffer overflow in addressbook/backends/ldap/e-book-backend-ldap.c
evolution-data-server: Unsafe use of strcat allows buffer overflow in addressbook/backends/ldap/e-book-backend-ldap.c
addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that is processed by the strcat function. NOTE: the software maintainer disputes this because "the code had computed the required string length first, and then allocated a large-enough buffer on the heap.
Package: evolution-data-server (Red Hat Enterprise Linux 5) - Will not fix
Package: evolution-data-server (Red Hat Enterprise Linux 6) - Will not fix
Package: evolution-data-server (Red Hat Enterprise Linux 7) - Will not fix
Package: evolution-data-server (Red Hat Enterprise Linux 8) - Not affect
Debian
CVE-2018-12422: evolution-data-server - addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOM...
vendor_debian·2018·CVSS 9.8
CVE-2018-12422 [CRITICAL] CVE-2018-12422: evolution-data-server - addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOM...
addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that is processed by the strcat function. NOTE: the software maintainer disputes this because "the code had computed the required string length first, and then allocated a large-enough buffer on the heap.
Scope: local
bookworm: resolved (fixed in 3.28.5-1)
bullseye: resolved (fixed in 3.28.5-1)
forky: resolved (fixed in 3.28.5-1)
sid: resolved (fixed in 3.28.5-1)
trixie: resolved (fixed in 3.28.5-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-12422 evolution-data-server: Unsafe use of strcat allows buffer overflow in addressbook/backends/ldap/e-book-backend-ldap.c [fedora-all]
bugzilla·2018-06-19·CVSS 9.8
CVE-2018-12422 [CRITICAL] CVE-2018-12422 evolution-data-server: Unsafe use of strcat allows buffer overflow in addressbook/backends/ldap/e-book-backend-ldap.c [fedora-all]
CVE-2018-12422 evolution-data-server: Unsafe use of strcat allows buffer overflow in addressbook/backends/ldap/e-book-backend-ldap.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg c
Bugzilla
CVE-2018-12422 evolution-data-server: Unsafe use of strcat allows buffer overflow in addressbook/backends/ldap/e-book-backend-ldap.c
bugzilla·2018-06-19·CVSS 9.8
CVE-2018-12422 [CRITICAL] CVE-2018-12422 evolution-data-server: Unsafe use of strcat allows buffer overflow in addressbook/backends/ldap/e-book-backend-ldap.c
CVE-2018-12422 evolution-data-server: Unsafe use of strcat allows buffer overflow in addressbook/backends/ldap/e-book-backend-ldap.c
Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a stack-based buffer overflow in addressbook/backends/ldap/e-book-backend-ldap.c via a long query that is processed by the strcat function.
Upstream Bug:
https://bugzilla.gnome.org/show_bug.cgi?id=796174
Upstream Patch:
https://gitlab.gnome.org/GNOME/evolution-data-server/commit/34bad6173
Discussion:
Created evolution-data-server tracking bugs for this issue:
Affects: fedora-all [bug 1592626]
---
(In reply to Sam Fowler from comment #0)
> Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow
> attackers to trigger a stack-based buffer overflow in
2018-06-15
Published