#VU17667 Spoofing attack in Evolution


Published: 2019-02-14

Vulnerability identifier: #VU17667

Vulnerability risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C]

CVE-ID: CVE-2018-15587

CWE-ID: CWE-451

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Evolution
Client/Desktop applications / Office applications

Vendor: Gnome Development Team

Description
The vulnerability allows a remote attacker to conduct spoofing attack.

The vulnerability exists due to improper validation of OpenPGP signatures. A remote attacker can trick the victim into opening a malicious email with valid PGP-signed data as an attachment and either inject arbitrary script code, which could be used to trick the user into disclosing sensitive information, or conduct further attacks.

Mitigation
Update to versions 3.28.3 or later.

Vulnerable software versions

Evolution: 3.0 - 3.29.3


External links
http://bugzilla.gnome.org/show_bug.cgi?id=796424
http://gitlab.gnome.org/GNOME/evolution/issues/120


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.


Latest bulletins with this vulnerability