CVE-2003-0128: Buffer Overflow
The tryuudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0128?
CVE-2003-0128 is classified as a denial of service vulnerability due to potential heap-based buffer overflow.
How do I fix CVE-2003-0128?
To fix CVE-2003-0128, it is recommended to upgrade to a later version of Ximian Evolution that addresses this vulnerability.
What versions of Ximian Evolution are affected by CVE-2003-0128?
Ximian Evolution versions 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.1.1, 1.2, 1.2.1, and 1.2.2 are affected by CVE-2003-0128.
Can CVE-2003-0128 allow remote code execution?
Yes, CVE-2003-0128 may allow remote attackers to execute arbitrary code via a malicious uuencoded header.
What type of attack does CVE-2003-0128 facilitate?
CVE-2003-0128 facilitates denial of service attacks and potentially remote code execution through a buffer overflow.