Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade evolution-data-server | Jul 30, 2024 | Feb 12, 2009 |
| Oracle_linux | — | Upgrade evolution-data-serverUpgrade evolution-data-server-docUpgrade evolution-data-server-devel | Oct 16, 2024 | Feb 12, 2009 |
| Suse | — | Upgrade evolution-data-server-x86Upgrade sap-aio-releaseUpgrade evolution-data-server-langUpgrade evolution-data-server-docUpgrade evolution-data-serverUpgrade evolution-data-server-32bitUpgrade evolution-data-server-develUpgrade evolution-data-server-64bit | Feb 17, 2015 | Feb 12, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub