[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-0528Date: (C)2006-02-02   (M)2023-12-22


The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to repeatedly crash until the e-mail message is manually removed, possibly due to a buffer overflow, as demonstrated using an XML attachment.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
BID-16408
SECUNIA-19504
http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0925.html
SREASON-610
MDKSA-2006:057
SUSE-SR:2006:007
USN-265-1

CPE    8
cpe:/a:gnome:evolution:2.3.1
cpe:/a:gnome:evolution:2.3.5
cpe:/a:gnome:evolution:2.3.4
cpe:/a:gnome:evolution:2.3.3
...

© SecPod Technologies