CVE-2009-0547 — Evolution vulnerability
7 documents7 sources
Severity
5.0MEDIUMNVD
CNA5.8OSV5.8
EPSS
3.4%
top 12.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 12
Latest updateMay 2
Description
Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.
CVSS vector
AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9
Affected Packages2 packages
🔴Vulnerability Details
3📋Vendor Advisories
2💬Community
1Bugzilla▶
CVE-2009-0547 evolution-data-server: S/MIME signatures are considered to be valid even for modified messages (MITM)↗2009-02-10