2018-06-19
ALT-BU-2018-3314-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Published: 2018-05-27
BDU:2019-02900
Уязвимость почтовой программы Evolution, связанная с некорректной проверкой криптографической подписи OpenPGP, позволяющая нарушителю оказать воздействие на целостность данных
Severity: MEDIUM (6.5)
Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
References:
Published: 2019-02-11
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-15587
GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment.
Severity: MEDIUM (6.5)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
References:
- openSUSE-SU-2019:1431
- openSUSE-SU-2019:1431
- openSUSE-SU-2019:1453
- openSUSE-SU-2019:1453
- openSUSE-SU-2019:1528
- openSUSE-SU-2019:1528
- http://packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.html
- http://packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.html
- 20190430 OpenPGP and S/MIME signature forgery attacks in multiple email clients
- 20190430 OpenPGP and S/MIME signature forgery attacks in multiple email clients
- [oss-security] 20190430 Spoofing OpenPGP and S/MIME Signatures in Emails (multiple clients)
- [oss-security] 20190430 Spoofing OpenPGP and S/MIME Signatures in Emails (multiple clients)
- https://bugzilla.gnome.org/show_bug.cgi?id=796424
- https://bugzilla.gnome.org/show_bug.cgi?id=796424
- https://github.com/RUB-NDS/Johnny-You-Are-Fired
- https://github.com/RUB-NDS/Johnny-You-Are-Fired
- https://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdf
- https://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdf
- [debian-lts-announce] 20190426 [SECURITY] [DLA 1766-1] evolution security update
- [debian-lts-announce] 20190426 [SECURITY] [DLA 1766-1] evolution security update
- 20190609 [SECURITY] [DSA 4457-1] evolution security update
- 20190609 [SECURITY] [DSA 4457-1] evolution security update
- USN-3998-1
- USN-3998-1
- DSA-4457
- DSA-4457