CVE-2006-0528: Buffer Overflow
The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to repeatedly crash until the e-mail message is manually removed, possibly due to a buffer overflow, as demonstrated using an XML attachment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0528?
CVE-2006-0528 is classified as a denial of service vulnerability that can lead to persistent client crashes.
How do I fix CVE-2006-0528?
To fix CVE-2006-0528, update the GNOME Evolution application to a version that addresses this issue.
Which versions of GNOME Evolution are affected by CVE-2006-0528?
Versions 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.3.6, 2.3.6.1, and 2.3.7 of GNOME Evolution are affected by CVE-2006-0528.
Can CVE-2006-0528 be exploited remotely?
Yes, CVE-2006-0528 can be exploited remotely through a specially crafted text file attachment.
What impact does CVE-2006-0528 have on users?
Users affected by CVE-2006-0528 may experience application crashes, leading to potential data loss and disruptions.