Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3349

Опубликовано: 01 фев. 2021
Источник: debian
EPSS Низкий

Описание

GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior

Пакеты

ПакетСтатусВерсия исправленияРелизТип
evolutionunfixedpackage

Примечания

  • GNOME Evlolution upstreams claims that the issue should be fixed completely

  • on the GnuPG side, whilst the reporter claims theat GnuPG provides what is

  • needed to adress it on evolution's side.

  • https://dev.gnupg.org/T4735

  • https://gitlab.gnome.org/GNOME/evolution/-/issues/299

  • https://mgorny.pl/articles/evolution-uid-trust-extrapolation.html

EPSS

Процентиль: 29%
0.00104
Низкий

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 5 лет назад

GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior

CVSS3: 2.9
redhat
около 5 лет назад

GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior

CVSS3: 3.3
nvd
около 5 лет назад

GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior

CVSS3: 3.3
github
больше 3 лет назад

** DISPUTED ** GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior.

EPSS

Процентиль: 29%
0.00104
Низкий