Debian Security Advisory

DSA-4457-1 evolution -- security update

Date Reported:
07 Jun 2019
Affected Packages:
Security database references:
In the Debian bugtracking system: Bug 924616.
In Mitre's CVE dictionary: CVE-2018-15587.
More information:

Hanno Böck discovered that Evolution was vulnerable to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted HTML email. This issue was mitigated by moving the security bar with encryption and signature information above the message headers.

For the stable distribution (stretch), this problem has been fixed in version 3.22.6-1+deb9u2.

We recommend that you upgrade your evolution packages.

For the detailed security status of evolution please refer to its security tracker page at: