CVE-2018-15587
Summary
| CVE | CVE-2018-15587 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-02-11 17:29:00 UTC |
| Updated | 2019-06-10 07:29:00 UTC |
| Description | GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [security-announce] openSUSE-SU-2019:1431-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| Johnny-You-Are-Fired/johnny-fired.pdf at master · RUB-NDS/Johnny-You-Are-Fired · GitHub |
MISC |
github.com |
|
| Bug 796424 – Signature Spoofing in PGP encrypted email |
MISC |
bugzilla.gnome.org |
Exploit, Issue Tracking, Vendor Advisory |
| [security-announce] openSUSE-SU-2019:1528-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| [SECURITY] [DLA 1766-1] evolution security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Debian -- Security Information -- DSA-4457-1 evolution |
DEBIAN |
www.debian.org |
|
| GitHub - RUB-NDS/Johnny-You-Are-Fired: Artifacts for the USENIX publication. |
MISC |
github.com |
|
| Bugtraq: [SECURITY] [DSA 4457-1] evolution security update |
BUGTRAQ |
seclists.org |
|
| [security-announce] openSUSE-SU-2019:1453-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| oss-security - Spoofing OpenPGP and S/MIME Signatures in Emails (multiple clients) |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| USN-3998-1: Evolution Data Server vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| Johnny You Are Fired ≈ Packet Storm |
MISC |
packetstormsecurity.com |
Third Party Advisory, VDB Entry |
| Full Disclosure: OpenPGP and S/MIME signature forgery attacks in multiple email clients |
FULLDISC |
seclists.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377251 Alibaba Cloud Linux Security Update for evolution (ALINUX2-SA-2020:0059)
- 670297 EulerOS Security Update for evolution (EulerOS-SA-2021-1779)
- 940368 AlmaLinux Security Update for evolution (ALSA-2020:1600)