Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade evolution-data-server | Jul 30, 2024 | Feb 12, 2009 |
| Oracle_linux | — | Upgrade evolution-data-serverUpgrade evolution-data-server-develUpgrade evolution-data-server-doc | Oct 16, 2024 | Feb 12, 2009 |
| Suse | — | Upgrade evolution-data-server-x86Upgrade evolution-data-server-32bitUpgrade evolution-data-serverUpgrade evolution-data-server-lang | Feb 17, 2015 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub