Back

MEDIUM

evolution-data-server: S/MIME signatures are considered to be valid even for modified messages (MITM)

Published Feb 12, 2009

Description

Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (25)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 12, 2009
Updated Aug 7, 2024
Reserved Feb 12, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Dec 11, 2008