First published: Thu May 30 2019(Updated: )
Marcus Brinkmann discovered that Evolution Data Server did not correctly interpret the output from GPG when decrypting encrypted messages. Under certain circumstances, this could result in displaying clear-text portions of encrypted messages as though they were encrypted.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/evolution-data-server | <3.28.5-0ubuntu0.18.04.2 | 3.28.5-0ubuntu0.18.04.2 |
=18.04 | ||
All of | ||
ubuntu/evolution-data-server-common | <3.28.5-0ubuntu0.18.04.2 | 3.28.5-0ubuntu0.18.04.2 |
=18.04 | ||
All of | ||
ubuntu/libcamel-1.2-61 | <3.28.5-0ubuntu0.18.04.2 | 3.28.5-0ubuntu0.18.04.2 |
=18.04 | ||
All of | ||
ubuntu/libebackend-1.2-10 | <3.28.5-0ubuntu0.18.04.2 | 3.28.5-0ubuntu0.18.04.2 |
=18.04 | ||
All of | ||
ubuntu/libedataserver-1.2-23 | <3.28.5-0ubuntu0.18.04.2 | 3.28.5-0ubuntu0.18.04.2 |
=18.04 | ||
All of | ||
ubuntu/evolution-data-server | <3.18.5-1ubuntu1.2 | 3.18.5-1ubuntu1.2 |
=16.04 | ||
All of | ||
ubuntu/evolution-data-server-common | <3.18.5-1ubuntu1.2 | 3.18.5-1ubuntu1.2 |
=16.04 | ||
All of | ||
ubuntu/libcamel-1.2-54 | <3.18.5-1ubuntu1.2 | 3.18.5-1ubuntu1.2 |
=16.04 | ||
All of | ||
ubuntu/libebackend-1.2-10 | <3.18.5-1ubuntu1.2 | 3.18.5-1ubuntu1.2 |
=16.04 | ||
All of | ||
ubuntu/libedataserver-1.2-21 | <3.18.5-1ubuntu1.2 | 3.18.5-1ubuntu1.2 |
=16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-3998-1 is high.
The vulnerability in USN-3998-1 allows for the display of clear-text portions of encrypted messages as though they were encrypted.
Versions 3.28.5-0ubuntu0.18.04.2 and earlier, and 3.18.5-1ubuntu1.2 and earlier are affected by USN-3998-1.
To fix the vulnerability in USN-3998-1, you should update Evolution Data Server to version 3.28.5-0ubuntu0.18.04.2 or later.
You can find more information about USN-3998-1 on the Ubuntu website.