First published: Tue Feb 10 2009(Updated: )
A man-in-the-middle-attack possibility was found in the way evolution handles the Secure / Multipurpose Internet Mail Extensions (S/MIME) mail messages. If the S/MIME email was sign, the email message subsequently modified, evolution would consider the S/MIME message signature to be valid even for such a modified message. An attacker could use this flaw to modify the emails (message integrity violation) between communicating part. References: <a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508479">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508479</a>
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME Evolution |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-484925 is considered high due to the potential for man-in-the-middle attacks.
To fix REDHAT-BUG-484925, update GNOME Evolution to the latest version that addresses this vulnerability.
REDHAT-BUG-484925 affects GNOME Evolution when handling S/MIME email messages.
REDHAT-BUG-484925 describes a man-in-the-middle attack due to improper validation of S/MIME signatures.
Currently, there are no documented workarounds for REDHAT-BUG-484925 aside from applying the necessary updates.