Red Hat Bugzilla – Bug 238565
CVE-2007-1558 Evolution APOP information disclosure
Last modified: 2009-06-10 04:59:35 EDT
+++ This bug was initially created as a clone of Bug #235289 +++
A flaw has been found in the way Evolution handles APOP authentication. It is
possible for an attacker to discover authentication credentials by sending
certain responses to Evolution.
The upstream bug has more details:
I'm moving to version to RHEL4. This flaw affects RHEL 3 and 4.
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.