Related Vulnerabilities: CVE-2021-3349  

GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior.

Severity Medium

Remote Yes

Type Insufficient validation

Description

GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior.

AVG-1516 evolution 3.38.3-1 Medium Vulnerable

https://mgorny.pl/articles/evolution-uid-trust-extrapolation.html
https://gitlab.gnome.org/GNOME/evolution/-/issues/299
https://dev.gnupg.org/T4735