Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2005:267 - Security Advisory
Issued:
2005-08-29
Updated:
2005-08-29

RHSA-2005:267 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Evolution security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Updated evolution packages that fix a format string issue are now available.

This update has been rated as having important security impact by the Red
Hat Security Response Team.

Description

Evolution is the GNOME collection of personal information management (PIM)
tools.

A format string bug was found in Evolution. If a user tries to save a
carefully crafted meeting or appointment, arbitrary code may be executed as
the user running Evolution. The Common Vulnerabilities and Exposures
project has assigned the name CAN-2005-2550 to this issue.

Additionally, several other format string bugs were found in Evolution. If
a user views a malicious vCard, connects to a malicious LDAP server, or
displays a task list from a malicious remote server, arbitrary code may be
executed as the user running Evolution. The Common Vulnerabilities and
Exposures project has assigned the name CAN-2005-2549 to this issue. Please
note that this issue only affects Red Hat Enterprise Linux 4.

All users of Evolution should upgrade to these updated packages, which
contain a backported patch which resolves this issue.

Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Affected Products

  • Red Hat Enterprise Linux Server 4 x86_64
  • Red Hat Enterprise Linux Server 4 ia64
  • Red Hat Enterprise Linux Server 4 i386
  • Red Hat Enterprise Linux Server 3 x86_64
  • Red Hat Enterprise Linux Server 3 ia64
  • Red Hat Enterprise Linux Server 3 i386
  • Red Hat Enterprise Linux Workstation 4 x86_64
  • Red Hat Enterprise Linux Workstation 4 ia64
  • Red Hat Enterprise Linux Workstation 4 i386
  • Red Hat Enterprise Linux Workstation 3 x86_64
  • Red Hat Enterprise Linux Workstation 3 ia64
  • Red Hat Enterprise Linux Workstation 3 i386
  • Red Hat Enterprise Linux Desktop 4 x86_64
  • Red Hat Enterprise Linux Desktop 4 i386
  • Red Hat Enterprise Linux Desktop 3 x86_64
  • Red Hat Enterprise Linux Desktop 3 i386
  • Red Hat Enterprise Linux for IBM z Systems 4 s390x
  • Red Hat Enterprise Linux for IBM z Systems 4 s390
  • Red Hat Enterprise Linux for IBM z Systems 3 s390x
  • Red Hat Enterprise Linux for IBM z Systems 3 s390
  • Red Hat Enterprise Linux for Power, big endian 4 ppc
  • Red Hat Enterprise Linux for Power, big endian 3 ppc

Fixes

  • BZ - 165235 - CAN-2005-2549 Sitic Vulnerability Advisory: SA05-001 Evolution multiple remote format string bugs (RHEL4) (CAN-2005-2550)
  • BZ - 165236 - CAN-2005-2550 Sitic Vulnerability Advisory: SA05-001 Evolution multiple remote format string bugs (RHEL3)

CVEs

  • CVE-2005-2549
  • CVE-2005-2550

References

(none)

Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server 4

SRPM
evolution-2.0.2-16.3.src.rpm SHA-256: f1d84a87b42658ee4c1fc48a8850e4204e0e7d808bb9b08d15bc527466a38a9d
x86_64
evolution-2.0.2-16.3.x86_64.rpm SHA-256: e25da0c65c8f3d75adf9e1036733fb0d20be28c7c6a975c51bd48bdecb88ee23
evolution-2.0.2-16.3.x86_64.rpm SHA-256: e25da0c65c8f3d75adf9e1036733fb0d20be28c7c6a975c51bd48bdecb88ee23
evolution-devel-2.0.2-16.3.x86_64.rpm SHA-256: 18cd9865a7b89e7fa21e69abf55775df7696530bb390ed3051838c95cc2f1685
evolution-devel-2.0.2-16.3.x86_64.rpm SHA-256: 18cd9865a7b89e7fa21e69abf55775df7696530bb390ed3051838c95cc2f1685
ia64
evolution-2.0.2-16.3.ia64.rpm SHA-256: ba9156793023a194f2b499ddb5e26bc8b5bbe61268ea632ee616d1dc4051f64a
evolution-2.0.2-16.3.ia64.rpm SHA-256: ba9156793023a194f2b499ddb5e26bc8b5bbe61268ea632ee616d1dc4051f64a
evolution-devel-2.0.2-16.3.ia64.rpm SHA-256: afb342fdd2692f2b0e29354344df0e3584ff43b5a11e086a4ccdc8b504f229fd
evolution-devel-2.0.2-16.3.ia64.rpm SHA-256: afb342fdd2692f2b0e29354344df0e3584ff43b5a11e086a4ccdc8b504f229fd
i386
evolution-2.0.2-16.3.i386.rpm SHA-256: c45d36c6191d124c4411a92c9e7f1ed9e5b17b37db7e4f1a202d13a88f7b5ee2
evolution-2.0.2-16.3.i386.rpm SHA-256: c45d36c6191d124c4411a92c9e7f1ed9e5b17b37db7e4f1a202d13a88f7b5ee2
evolution-devel-2.0.2-16.3.i386.rpm SHA-256: c79a13fcaec9e6fa24ec43b2cf6a0296b78ff5e299578b9e2ee0f3b886391b7f
evolution-devel-2.0.2-16.3.i386.rpm SHA-256: c79a13fcaec9e6fa24ec43b2cf6a0296b78ff5e299578b9e2ee0f3b886391b7f

Red Hat Enterprise Linux Server 3

SRPM
x86_64
ia64
i386

Red Hat Enterprise Linux Workstation 4

SRPM
evolution-2.0.2-16.3.src.rpm SHA-256: f1d84a87b42658ee4c1fc48a8850e4204e0e7d808bb9b08d15bc527466a38a9d
x86_64
evolution-2.0.2-16.3.x86_64.rpm SHA-256: e25da0c65c8f3d75adf9e1036733fb0d20be28c7c6a975c51bd48bdecb88ee23
evolution-devel-2.0.2-16.3.x86_64.rpm SHA-256: 18cd9865a7b89e7fa21e69abf55775df7696530bb390ed3051838c95cc2f1685
ia64
evolution-2.0.2-16.3.ia64.rpm SHA-256: ba9156793023a194f2b499ddb5e26bc8b5bbe61268ea632ee616d1dc4051f64a
evolution-devel-2.0.2-16.3.ia64.rpm SHA-256: afb342fdd2692f2b0e29354344df0e3584ff43b5a11e086a4ccdc8b504f229fd
i386
evolution-2.0.2-16.3.i386.rpm SHA-256: c45d36c6191d124c4411a92c9e7f1ed9e5b17b37db7e4f1a202d13a88f7b5ee2
evolution-devel-2.0.2-16.3.i386.rpm SHA-256: c79a13fcaec9e6fa24ec43b2cf6a0296b78ff5e299578b9e2ee0f3b886391b7f

Red Hat Enterprise Linux Workstation 3

SRPM
x86_64
ia64
i386

Red Hat Enterprise Linux Desktop 4

SRPM
evolution-2.0.2-16.3.src.rpm SHA-256: f1d84a87b42658ee4c1fc48a8850e4204e0e7d808bb9b08d15bc527466a38a9d
x86_64
evolution-2.0.2-16.3.x86_64.rpm SHA-256: e25da0c65c8f3d75adf9e1036733fb0d20be28c7c6a975c51bd48bdecb88ee23
evolution-devel-2.0.2-16.3.x86_64.rpm SHA-256: 18cd9865a7b89e7fa21e69abf55775df7696530bb390ed3051838c95cc2f1685
i386
evolution-2.0.2-16.3.i386.rpm SHA-256: c45d36c6191d124c4411a92c9e7f1ed9e5b17b37db7e4f1a202d13a88f7b5ee2
evolution-devel-2.0.2-16.3.i386.rpm SHA-256: c79a13fcaec9e6fa24ec43b2cf6a0296b78ff5e299578b9e2ee0f3b886391b7f

Red Hat Enterprise Linux Desktop 3

SRPM
x86_64
i386

Red Hat Enterprise Linux for IBM z Systems 4

SRPM
evolution-2.0.2-16.3.src.rpm SHA-256: f1d84a87b42658ee4c1fc48a8850e4204e0e7d808bb9b08d15bc527466a38a9d
s390x
evolution-2.0.2-16.3.s390x.rpm SHA-256: e6311e2b05d6ba0c8779dffe0b3a56ec992502ee8ec1878268de4f82fb41c0cb
evolution-devel-2.0.2-16.3.s390x.rpm SHA-256: e1c621985bbbab6912c864414d3f8ee8ff9873b7285e85d3a4cdf3433b6428db
s390
evolution-2.0.2-16.3.s390.rpm SHA-256: 26f567be5c7df8689895b51d77a4ead12e0ec1a1b6179a7b33a638947866b488
evolution-devel-2.0.2-16.3.s390.rpm SHA-256: 67551c2b6d48b9f6c52557f14d261e98901ab456ca1d96e84010611cf4b39758

Red Hat Enterprise Linux for IBM z Systems 3

SRPM
s390x
s390

Red Hat Enterprise Linux for Power, big endian 4

SRPM
evolution-2.0.2-16.3.src.rpm SHA-256: f1d84a87b42658ee4c1fc48a8850e4204e0e7d808bb9b08d15bc527466a38a9d
ppc
evolution-2.0.2-16.3.ppc.rpm SHA-256: 12219f37c8c32070d9fae4aa5326a1b436e19e8d2ecd7c2824f5ca0fe4d29204
evolution-devel-2.0.2-16.3.ppc.rpm SHA-256: cb18c50d73a5b5e5414a674ce30a8ec24a864475bc72f85ee0a68b81575e4ebf

Red Hat Enterprise Linux for Power, big endian 3

SRPM
ppc

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility