CVE-2008-1109

Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar attachment, which is not properly handled during a reply in the calendar view (aka the Calendars window).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
flexeraCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
gnomeevolution
2.22.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
evolution
bullseye (security)
3.38.3-1+deb11u2
fixed
bullseye
3.38.3-1+deb11u2
fixed
etch
no-dsa
bookworm
3.46.4-2
fixed
sid
3.54.1-1
fixed
trixie
3.54.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
evolution
hardy
Fixed 2.22.2-0ubuntu1.2
released
gutsy
Fixed 2.12.1-0ubuntu1.3
released
feisty
Fixed 2.10.1-0ubuntu2.4
released
dapper
Fixed 2.6.1-0ubuntu7.4
released
References