CVE-2008-1108

Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attachment.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.6 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
flexeraCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
gnomeevolution
2.2.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
evolution
bullseye (security)
3.38.3-1+deb11u2
fixed
bullseye
3.38.3-1+deb11u2
fixed
etch
no-dsa
bookworm
3.46.4-2
fixed
sid
3.54.1-1
fixed
trixie
3.54.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
evolution
hardy
Fixed 2.22.2-0ubuntu1.2
released
gutsy
Fixed 2.12.1-0ubuntu1.3
released
feisty
Fixed 2.10.1-0ubuntu2.4
released
dapper
Fixed 2.6.1-0ubuntu7.4
released
References