DESCRIPTION
Evolution[1] is the GNOME mailer, calendar, contact manager and
communications tool.
Max Vozeler discovered an integer overflow[2] in the helper
application camel-lock-helper. A local attacker can cause the helper
to execute arbitrary code only with the current user privileges
privileges via a malicious POP server becose it is not setuid root
neither setgid mail.
For Conectiva Linux 10, Evolution is also having a major upgrade to
2.0.3, as requested by users.
SOLUTION
It is recommended that all Evolution users upgade their packages.
IMPORTANT: It is necessary to restart the application after the
upgrade in order to properly close the vulnerability.