DSA-4457-1 evolution -- security update

Related Vulnerabilities: CVE-2018-15587  

Hanno Böck discovered that Evolution was vulnerable to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted HTML email. This issue was mitigated by moving the security bar with encryption and signature information above the message headers. For the stable distribution (stretch), this problem has been fixed in version 3.22.6-1+deb9u2. We recommend that you upgrade your evolution packages. For the detailed security status of evolution please refer to its security tracker page at: https://security-tracker.debian.org/tracker/evolution

Debian Security Advisory

DSA-4457-1 evolution -- security update

Date Reported:
07 Jun 2019
Affected Packages:
evolution
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 924616.
In Mitre's CVE dictionary: CVE-2018-15587.
More information:

Hanno Böck discovered that Evolution was vulnerable to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted HTML email. This issue was mitigated by moving the security bar with encryption and signature information above the message headers.

For the stable distribution (stretch), this problem has been fixed in version 3.22.6-1+deb9u2.

We recommend that you upgrade your evolution packages.

For the detailed security status of evolution please refer to its security tracker page at: https://security-tracker.debian.org/tracker/evolution