PT-2021-20151 · Gnome+2 · Gnome Evolution+2

Published

2021-02-01

·

Updated

2024-08-03

·

CVE-2021-3349

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GNOME Evolution versions 3.38.3 and earlier
Description The issue arises when GNOME Evolution produces a "Valid signature" message for an unknown identifier on a previously trusted key. This occurs because Evolution does not retrieve enough information from the GnuPG API. It is noted that third parties dispute the significance of this issue and question whether Evolution is the best place to change this behavior.
Recommendations For GNOME Evolution versions 3.38.3 and earlier, as a temporary workaround, consider restricting the use of the GnuPG API to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1315
CVE-2021-3349

Affected Products

Alt Linux
Debian
Gnome Evolution