#VU17667 Spoofing attack in Evolution - CVE-2018-15587

 

#VU17667 Spoofing attack in Evolution - CVE-2018-15587

Published: February 14, 2019


Vulnerability identifier: #VU17667
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2018-15587
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Evolution
Software vendor:
Gnome Development Team

Description

The vulnerability allows a remote attacker to conduct spoofing attack.

The vulnerability exists due to improper validation of OpenPGP signatures. A remote attacker can trick the victim into opening a malicious email with valid PGP-signed data as an attachment and either inject arbitrary script code, which could be used to trick the user into disclosing sensitive information, or conduct further attacks.


Remediation

Update to versions 3.28.3 or later.

External links