A flaw has been found in the way Evolution handles APOP authentication. It is
possible for an attacker to discover authentication credentials by sending
certain responses to Evolution.
The upstream bug has more details:
This flaw should also affect RHEL 3 and 4.
*** Bug 238564 has been marked as a duplicate of this bug. ***
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.