ALAS2-2020-1476

Related Vulnerabilities: CVE-2018-15587  

GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment. (CVE-2018-15587)

ALAS2-2020-1476


Amazon Linux 2 Security Advisory: ALAS-2020-1476
Advisory Release Date: 2020-08-18 19:48 Pacific
Advisory Updated Date: 2020-08-25 00:00 Pacific
Severity: Medium
References: CVE-2018-15587 

Issue Overview:

GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment. (CVE-2018-15587)


Affected Packages:

evolution


Issue Correction:
Run yum update evolution to update your system.

New Packages:
aarch64:
    evolution-3.28.5-8.amzn2.aarch64
    evolution-devel-3.28.5-8.amzn2.aarch64
    evolution-bogofilter-3.28.5-8.amzn2.aarch64
    evolution-spamassassin-3.28.5-8.amzn2.aarch64
    evolution-pst-3.28.5-8.amzn2.aarch64
    evolution-debuginfo-3.28.5-8.amzn2.aarch64

i686:
    evolution-3.28.5-8.amzn2.i686
    evolution-devel-3.28.5-8.amzn2.i686
    evolution-bogofilter-3.28.5-8.amzn2.i686
    evolution-spamassassin-3.28.5-8.amzn2.i686
    evolution-pst-3.28.5-8.amzn2.i686
    evolution-debuginfo-3.28.5-8.amzn2.i686

noarch:
    evolution-devel-docs-3.28.5-8.amzn2.noarch
    evolution-langpacks-3.28.5-8.amzn2.noarch
    evolution-help-3.28.5-8.amzn2.noarch

src:
    evolution-3.28.5-8.amzn2.src

x86_64:
    evolution-3.28.5-8.amzn2.x86_64
    evolution-devel-3.28.5-8.amzn2.x86_64
    evolution-bogofilter-3.28.5-8.amzn2.x86_64
    evolution-spamassassin-3.28.5-8.amzn2.x86_64
    evolution-pst-3.28.5-8.amzn2.x86_64
    evolution-debuginfo-3.28.5-8.amzn2.x86_64