First published: Mon Feb 18 2019(Updated: )
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gnome Evolution-ews | <3.31.3 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
redhat/evolution-ewx | <3.31.3 | 3.31.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.