Spoofing attack in Evolution - CVE-2018-15587

 

Spoofing attack in Evolution - CVE-2018-15587

Published: February 14, 2019


Vulnerability identifier: #VU17667
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15587
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conduct spoofing attack.

The vulnerability exists due to improper validation of OpenPGP signatures. A remote attacker can trick the victim into opening a malicious email with valid PGP-signed data as an attachment and either inject arbitrary script code, which could be used to trick the user into disclosing sensitive information, or conduct further attacks.


Affected software

Evolution
Arch Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Opensuse
Fedora
evolution-data-server (Ubuntu package)
evolution (Debian package)
evolution-ews (Red Hat package)
evolution (Red Hat package)
evolution-data-server (Red Hat package)
evolution
Data Computing Appliance (DCA)

How to mitigate CVE-2018-15587

Update to versions 3.28.3 or later.

Evolution - update to 3.28.3
evolution-data-server (Ubuntu package) - addressed in versions 3.18.5-1ubuntu1.2, 3.28.5-0ubuntu0.18.04.2
evolution (Debian package) - update to 3.22.6-1+deb9u2
evolution-ews (Red Hat package) - update to 3.28.5-9.el8
evolution (Red Hat package) - update to 3.28.5-12.el8
evolution-data-server (Red Hat package) - update to 3.28.5-13.el8
evolution - update to 3.28.5-3.fc28
Data Computing Appliance (DCA) - update to 4.3.0.0

External References

Related Security Bulletins