#VU17667 Spoofing attack in Evolution - CVE-2018-15587
Published: February 14, 2019
Evolution
Gnome Development Team
Description
The vulnerability exists due to improper validation of OpenPGP signatures. A remote attacker can trick the victim into opening a malicious email with valid PGP-signed data as an attachment and either inject arbitrary script code, which could be used to trick the user into disclosing sensitive information, or conduct further attacks.