CVE-2009-0547
CVE-2009-0547
Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508479http://bugzilla.gnome.org/show_bug.cgi?id=564465http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.htmlhttp://openwall.com/lists/oss-security/2009/02/10/7https://bugzilla.redhat.com/show_bug.cgi?id=484925http://secunia.com/advisories/33848http://secunia.com/advisories/34338http://secunia.com/advisories/34339http://secunia.com/advisories/34363http://secunia.com/advisories/35357