Information Disclosure and Denial of Service in Evolution Data Server by Red Hat
CVE-2009-0582

Currently unrated

Key Information:

Vendor
Gnome
Vendor
CVE Published:
14 March 2009

Summary

A flaw in the ntlm_challenge function within the NTLM SASL authentication mechanism of Evolution Data Server allows remote mail servers to exploit inconsistent length checks in challenge packets. This inadequacy can lead to unauthorized information being accessed from the client’s memory or cause application crashes, compromising both user security and system stability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.