Hanno Böck discovered that Evolution was vulnerable to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted HTML email. This issue was mitigated by moving the security bar with encryption and signature information above the message headers. For the stable distribution (stretch), this problem has been fixed in version 3.22.6-1+deb9u2. We recommend that you upgrade your evolution packages. For the detailed security status of evolution please refer to its security tracker page at: https://security-tracker.debian.org/tracker/evolution
Hanno Böck discovered that Evolution was vulnerable to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted HTML email. This issue was mitigated by moving the security bar with encryption and signature information above the message headers.
For the stable distribution (stretch), this problem has been fixed in version 3.22.6-1+deb9u2.
We recommend that you upgrade your evolution packages.
For the detailed security status of evolution please refer to its security tracker page at: https://security-tracker.debian.org/tracker/evolution