CVE Vulnerabilities

CVE-2018-15587

Improper Verification of Cryptographic Signature

Published: Feb 11, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
5.4 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

NameVendorStart VersionEnd Version
EvolutionGnome*3.28.2 (including)
Red Hat Enterprise Linux 7RedHatatk-0:2.28.1-2.el7*
Red Hat Enterprise Linux 7RedHatevolution-0:3.28.5-8.el7*
Red Hat Enterprise Linux 7RedHatevolution-data-server-0:3.28.5-4.el7*
Red Hat Enterprise Linux 7RedHatevolution-ews-0:3.28.5-5.el7*
Red Hat Enterprise Linux 8RedHatevolution-0:3.28.5-12.el8*
Red Hat Enterprise Linux 8RedHatevolution-data-server-0:3.28.5-13.el8*
Red Hat Enterprise Linux 8RedHatevolution-ews-0:3.28.5-9.el8*
EvolutionUbuntubionic*
EvolutionUbuntucosmic*
EvolutionUbuntudevel*
EvolutionUbuntudisco*
EvolutionUbuntueoan*
EvolutionUbuntuesm-apps/bionic*
EvolutionUbuntuesm-apps/focal*
EvolutionUbuntuesm-apps/jammy*
EvolutionUbuntuesm-apps/noble*
EvolutionUbuntuesm-apps/xenial*
EvolutionUbuntufocal*
EvolutionUbuntugroovy*
EvolutionUbuntuhirsute*
EvolutionUbuntuimpish*
EvolutionUbuntujammy*
EvolutionUbuntukinetic*
EvolutionUbuntulunar*
EvolutionUbuntumantic*
EvolutionUbuntunoble*
EvolutionUbuntuoracular*
EvolutionUbuntuplucky*
EvolutionUbuntuquesting*
EvolutionUbuntutrusty*
EvolutionUbuntuxenial*
Evolution-data-serverUbuntubionic*
Evolution-data-serverUbuntucosmic*
Evolution-data-serverUbuntudevel*
Evolution-data-serverUbuntudisco*
Evolution-data-serverUbuntueoan*
Evolution-data-serverUbuntuesm-infra/bionic*
Evolution-data-serverUbuntuesm-infra/focal*
Evolution-data-serverUbuntuesm-infra/xenial*
Evolution-data-serverUbuntufocal*
Evolution-data-serverUbuntugroovy*
Evolution-data-serverUbuntuhirsute*
Evolution-data-serverUbuntuimpish*
Evolution-data-serverUbuntujammy*
Evolution-data-serverUbuntukinetic*
Evolution-data-serverUbuntulunar*
Evolution-data-serverUbuntumantic*
Evolution-data-serverUbuntunoble*
Evolution-data-serverUbuntuoracular*
Evolution-data-serverUbuntuplucky*
Evolution-data-serverUbuntuquesting*
Evolution-data-serverUbuntutrusty*
Evolution-data-serverUbuntuxenial*

References