CVE-2009-0547Evolution vulnerability

7 documents7 sources
Severity
5.0MEDIUMNVD
CNA5.8OSV5.8
EPSS
3.4%
top 12.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12
Latest updateMay 2

Description

Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debiangnome/evolution-data-server< 2.24.5-2+3
NVDevolution/evolution2.22.3.1

🔴Vulnerability Details

3
GHSA
GHSA-gq89-cf9v-xh3g: Evolution 22022-05-02
OSV
CVE-2009-0547: Evolution 22009-02-12
CVEList
CVE-2009-0547: Evolution 22009-02-12

📋Vendor Advisories

2
Debian
CVE-2009-0547: evolution-data-server - Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text wi...2009
Red Hat
evolution-data-server: S/MIME signatures are considered to be valid even for modified messages (MITM)2008-12-11

💬Community

1
Bugzilla
CVE-2009-0547 evolution-data-server: S/MIME signatures are considered to be valid even for modified messages (MITM)2009-02-10
CVE-2009-0547 — Evolution vulnerability | cvebase