CVE-2018-12422 describes a potential buffer overflow vulnerability in Evolution-Data-Server within GNOME Evolution through version 3.29.2. This flaw, located in the addressbook/backends/ldap/e-book-backend-ldap.c file, could be triggered by a long query processed by the strcat function, though the maintainer disputes this claim. With a CVSS score of 9.8 (Critical), the vulnerability has a network attack vector, low attack complexity, and could lead to high impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.29.2CPE matchmatch criteria | cpe:2.3:a:gnome:evolution:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.