GNOME Bugzilla – Bug 641069
downstream bnc #658194 tnef plugin directory traversal and buffer overflow vulnerabilities
Last modified: 2013-09-13 01:09:41 UTC
Created attachment 179741 [details] [review] Evolution Patch This patch solves the directory traversal and directory traversal vulnerabilities found in tnef plugins.
Though i couldn't test it well but it should solve the issue.
Go ahead and commit. That plugin (and tnef itself) is so badly written that I imagine it's rife with security issues. I don't see us moving it out of the "experimental" group anytime soon.
Patch committed to master. http://git.gnome.org/browse/evolution/commit/?id=a9fb511ced4cfaffb7109e58a9db66e6279e309c