Evolution has critical flaw
Security service provider Secunia has reported a critical flaw in the Evolution e-mail and groupware program. Attackers can use crafted e-mails to exploit a programming flaw that allows them to execute their own code with the rights of the logged-on user when an e-mail is opened.
Secunia's Ulf Harnhammar discovered the way to code to inject and execute code. When version data from an encrypted email are displayed by the emf_multipart_encrypted() function, a format string error can occur.
Secunia recommends users not to open untrusted e-mails. To be on the safe side, Evolution should be completely avoided for the time being. In its security advisory, Secunia says that various Linux distributors will soon be providing patches.
See also:
- Evolution Encrypted Message Format String Vulnerability, Secunia's security advisory
(mba)








![Kernel Log: Coming in 3.10 (Part 3) [--] Infrastructure](/imgs/43/1/0/4/2/6/7/2/comingin310_4_kicker-4977194bfb0de0d7.png)

![Kernel Log: Coming in 3.10 (Part 3) [--] Infrastructure](/imgs/43/1/0/4/2/3/2/3/comingin310_3_kicker-151cd7b9e9660f05.png)








