CVE-2021-3349
published 2021-02-01CVE-2021-3349: GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve…
PriorityP49low3.3CVSS 3.1
AVLACLPRLUINSUCNILAN
EPSS
0.35%
26.8th percentile
GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | evolution | — | — |
| gnome | evolution | <= 3.38.3 | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
evolution-data-server: mail is shown as having a valid signature from an unknown identifier on a previously trusted key
vendor_redhat·2021-02-01·CVSS 3.3
CVE-2021-3349 [LOW] CWE-345 evolution-data-server: mail is shown as having a valid signature from an unknown identifier on a previously trusted key
evolution-data-server: mail is shown as having a valid signature from an unknown identifier on a previously trusted key
GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior
Package: evolution-data-server (Red Hat Enterprise Linux 6) - Out of support scope
Package: evolution-data-server (Red Hat Enterprise Linux 7) - Out of support scope
Package: evolution-data-server (Red Hat Enterprise Linux 8) - Fix deferred
Package: evolution-data-server (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2021-3349: evolution - GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unkno...
vendor_debian·2021·CVSS 3.3
CVE-2021-3349 [LOW] CVE-2021-3349: evolution - GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unkno...
GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-q5mm-jcp2-mc43: ** DISPUTED ** GNOME Evolution through 3
ghsa_unreviewed·2022-05-24
CVE-2021-3349 [LOW] CWE-345 GHSA-q5mm-jcp2-mc43: ** DISPUTED ** GNOME Evolution through 3
** DISPUTED ** GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior.
OSV
CVE-2021-3349: ** DISPUTED ** GNOME Evolution through 3
osv·2021-02-01·CVSS 3.3
CVE-2021-3349 [LOW] CVE-2021-3349: ** DISPUTED ** GNOME Evolution through 3
** DISPUTED ** GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior.
OSV
CVE-2021-3349: GNOME Evolution through 3
osv·2021-02-01·CVSS 3.3
CVE-2021-3349 [LOW] CVE-2021-3349: GNOME Evolution through 3
GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-02-01
Published