Spoofing attack in Evolution - CVE-2018-15587
Published: February 14, 2019
Vulnerability details
The vulnerability exists due to improper validation of OpenPGP signatures. A remote attacker can trick the victim into opening a malicious email with valid PGP-signed data as an attachment and either inject arbitrary script code, which could be used to trick the user into disclosing sensitive information, or conduct further attacks.
Affected software
Arch Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Opensuse
Fedora
evolution-data-server (Ubuntu package)
evolution (Debian package)
evolution-ews (Red Hat package)
evolution (Red Hat package)
evolution-data-server (Red Hat package)
evolution
Data Computing Appliance (DCA)
How to mitigate CVE-2018-15587
evolution-data-server (Ubuntu package) - addressed in versions 3.18.5-1ubuntu1.2, 3.28.5-0ubuntu0.18.04.2
evolution (Debian package) - update to 3.22.6-1+deb9u2
evolution-ews (Red Hat package) - update to 3.28.5-9.el8
evolution (Red Hat package) - update to 3.28.5-12.el8
evolution-data-server (Red Hat package) - update to 3.28.5-13.el8
evolution - update to 3.28.5-3.fc28
Data Computing Appliance (DCA) - update to 4.3.0.0
External References
Related Security Bulletins
- Spoofing attack in GNOME Evolution
- Arch Linux update for evolution
- Arch Linux update for evolution
- OpenSUSE Linux update for evolution
- OpenSUSE Linux update for evolution
- Ubuntu update for Evolution Data Server
- Debian update for evolution
- OpenSUSE Linux update for evolution
- Red Hat update for evolution
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Fedora 28 update for evolution