CVE Vulnerabilities

CVE-2018-15587

Improper Verification of Cryptographic Signature

Published: Feb 11, 2019 | Modified: Jun 10, 2019
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
5.4 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Ubuntu
MEDIUM

GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Evolution Gnome * 3.28.2 (including)
Red Hat Enterprise Linux 7 RedHat atk-0:2.28.1-2.el7 *
Red Hat Enterprise Linux 7 RedHat evolution-0:3.28.5-8.el7 *
Red Hat Enterprise Linux 7 RedHat evolution-data-server-0:3.28.5-4.el7 *
Red Hat Enterprise Linux 7 RedHat evolution-ews-0:3.28.5-5.el7 *
Red Hat Enterprise Linux 8 RedHat evolution-0:3.28.5-12.el8 *
Red Hat Enterprise Linux 8 RedHat evolution-data-server-0:3.28.5-13.el8 *
Red Hat Enterprise Linux 8 RedHat evolution-ews-0:3.28.5-9.el8 *
Evolution Ubuntu bionic *
Evolution Ubuntu cosmic *
Evolution Ubuntu devel *
Evolution Ubuntu disco *
Evolution Ubuntu eoan *
Evolution Ubuntu esm-apps/bionic *
Evolution Ubuntu esm-apps/xenial *
Evolution Ubuntu focal *
Evolution Ubuntu groovy *
Evolution Ubuntu hirsute *
Evolution Ubuntu impish *
Evolution Ubuntu jammy *
Evolution Ubuntu kinetic *
Evolution Ubuntu lunar *
Evolution Ubuntu mantic *
Evolution Ubuntu noble *
Evolution Ubuntu oracular *
Evolution Ubuntu trusty *
Evolution Ubuntu xenial *
Evolution-data-server Ubuntu bionic *
Evolution-data-server Ubuntu cosmic *
Evolution-data-server Ubuntu devel *
Evolution-data-server Ubuntu disco *
Evolution-data-server Ubuntu eoan *
Evolution-data-server Ubuntu focal *
Evolution-data-server Ubuntu groovy *
Evolution-data-server Ubuntu hirsute *
Evolution-data-server Ubuntu impish *
Evolution-data-server Ubuntu jammy *
Evolution-data-server Ubuntu kinetic *
Evolution-data-server Ubuntu lunar *
Evolution-data-server Ubuntu mantic *
Evolution-data-server Ubuntu noble *
Evolution-data-server Ubuntu oracular *
Evolution-data-server Ubuntu trusty *
Evolution-data-server Ubuntu xenial *

References