First published: Mon Feb 01 2021(Updated: )
** DISPUTED ** GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME Evolution | <=3.38.3 | |
<=3.38.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-3349.
The severity of CVE-2021-3349 is low.
GNOME Evolution versions up to 3.38.3 are affected by CVE-2021-3349.
CVE-2021-3349 is a disputed vulnerability in GNOME Evolution that produces a "Valid signature" message for an unknown identifier on a previously trusted key due to insufficient retrieval of information from the GnuPG API.
Yes, you can find references for CVE-2021-3349 at the following links: [1] [2] [3]