Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-0547

Опубликовано: 11 дек. 2008
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=484925evolution-data-server: S/MIME signatures are considered to be valid even for modified messages (MITM)

EPSS

Процентиль: 87%
0.03409
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 16 лет назад

Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.

nvd
больше 16 лет назад

Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.

debian
больше 16 лет назад

Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-ma ...

github
около 3 лет назад

Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.

oracle-oval
больше 16 лет назад

ELSA-2009-0354: evolution-data-server security update (MODERATE)

EPSS

Процентиль: 87%
0.03409
Низкий

5 Medium

CVSS2