CVE-2018-15587: Medium severity Gnome Evolution vulnerability
Published Feb 11, 2019
·Updated
GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment.
Affected Software
3 affected componentsFixes available
Gnome Evolution<=3.28.2
Debian Debian Linux=8.0
debian/evolution
3.38.3-1+deb11u23.38.3-1+deb11u33.46.4-2+deb12u13.56.2-0+deb13u13.56.1-1+deb13u13.56.2-8
Remediation
Event History
Feb 11, 2019
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Feb 15, 2019
Data Sourced
via Red Hat·01:42 PM
DescriptionSeverityAffected Software
Mar 14, 2019
Data Sourced
10:21 PM
SeverityAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:52 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·05:20 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·05:21 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this GNOME Evolution vulnerability?
The vulnerability ID for this GNOME Evolution vulnerability is CVE-2018-15587.
2
What is the severity of CVE-2018-15587?
The severity of CVE-2018-15587 is medium.
3
Which software versions are affected by CVE-2018-15587?
GNOME Evolution through 3.28.2 is affected by CVE-2018-15587.
4
How can the OpenPGP signatures spoofing vulnerability be exploited?
The OpenPGP signatures spoofing vulnerability can be exploited by using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment.
5
Are there any remedies available for CVE-2018-15587?
Yes, the remediation for CVE-2018-15587 is to update to version 3.31.90-1 or later.