CVE Vulnerabilities

CVE-2018-15587

Improper Verification of Cryptographic Signature

Published: Feb 11, 2019 | Modified: Jun 10, 2019
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
5.4 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Ubuntu

GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment.

Weakness

The software does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Evolution Gnome * 3.28.2
Red Hat Enterprise Linux 7 RedHat atk-0:2.28.1-2.el7 *
Red Hat Enterprise Linux 7 RedHat evolution-0:3.28.5-8.el7 *
Red Hat Enterprise Linux 7 RedHat evolution-data-server-0:3.28.5-4.el7 *
Red Hat Enterprise Linux 7 RedHat evolution-ews-0:3.28.5-5.el7 *
Red Hat Enterprise Linux 8 RedHat evolution-0:3.28.5-12.el8 *
Red Hat Enterprise Linux 8 RedHat evolution-data-server-0:3.28.5-13.el8 *
Red Hat Enterprise Linux 8 RedHat evolution-ews-0:3.28.5-9.el8 *
Evolution Ubuntu bionic *
Evolution Ubuntu cosmic *
Evolution Ubuntu devel *
Evolution Ubuntu disco *
Evolution Ubuntu eoan *
Evolution Ubuntu focal *
Evolution Ubuntu groovy *
Evolution Ubuntu hirsute *
Evolution Ubuntu impish *
Evolution Ubuntu jammy *
Evolution Ubuntu trusty *
Evolution Ubuntu xenial *
Evolution-data-server Ubuntu bionic *
Evolution-data-server Ubuntu cosmic *
Evolution-data-server Ubuntu devel *
Evolution-data-server Ubuntu disco *
Evolution-data-server Ubuntu eoan *
Evolution-data-server Ubuntu esm-infra/xenial *
Evolution-data-server Ubuntu focal *
Evolution-data-server Ubuntu groovy *
Evolution-data-server Ubuntu hirsute *
Evolution-data-server Ubuntu impish *
Evolution-data-server Ubuntu jammy *
Evolution-data-server Ubuntu trusty *
Evolution-data-server Ubuntu xenial *

References