evolution-data-server vulnerability

Related Vulnerabilities: CVE-2013-4166  

Evolution would sometimes encrypt email to the wrong recipient.

Yves-Alexis Perez discovered that Evolution Data Server did not properly select GPG recipients. Under certain circumstances, this could result in Evolution encrypting email to an unintended recipient.

31 July 2013

evolution-data-server vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 13.04
  • Ubuntu 12.10
  • Ubuntu 12.04 LTS

Summary

Evolution would sometimes encrypt email to the wrong recipient.

Software Description

  • evolution-data-server - Evolution suite data server

Details

Yves-Alexis Perez discovered that Evolution Data Server did not properly select GPG recipients. Under certain circumstances, this could result in Evolution encrypting email to an unintended recipient.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 13.04
libcamel-1.2-40 - 3.6.4-0ubuntu1.1
Ubuntu 12.10
libcamel-1.2-40 - 3.6.2-0ubuntu0.2
Ubuntu 12.04 LTS
libcamel-1.2-29 - 3.2.3-0ubuntu7.1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to restart Evolution to make all the necessary changes.

References