Vulnerability Name:

CVE-2009-0547 (CCN-48666)

Assigned:2008-12-11
Published:2008-12-11
Updated:2017-09-29
Summary:Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.
CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
3.5 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N)
1.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.0 Medium (REDHAT CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
3.5 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-310
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Debian Bug report logs - #508479
evolution shows a SMIME signed messages as ok even if modified

Source: MISC
Type: UNKNOWN
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508479

Source: CCN
Type: GNOME Bugzilla Bug 564465
Wrong signature marked as valid on modified mail messages

Source: CONFIRM
Type: UNKNOWN
http://bugzilla.gnome.org/show_bug.cgi?id=564465

Source: MITRE
Type: CNA
CVE-2009-0547

Source: SUSE
Type: UNKNOWN
SUSE-SR:2010:006

Source: SUSE
Type: UNKNOWN
SUSE-SR:2010:011

Source: SUSE
Type: UNKNOWN
SUSE-SR:2010:012

Source: MLIST
Type: UNKNOWN
[oss-security] 20090210 CVE Request -- evolution

Source: CCN
Type: Evolution Web site
Evolution

Source: CCN
Type: RHSA-2009-0354
Moderate: evolution-data-server security update

Source: CCN
Type: RHSA-2009-0355
Moderate: evolution and evolution-data-server security update

Source: CCN
Type: SA33848
Evolution S/MIME Signed Message Integrity Vulnerability

Source: SECUNIA
Type: Vendor Advisory
33848

Source: CCN
Type: SA34338
Red Hat update for evolution-data-server

Source: SECUNIA
Type: UNKNOWN
34338

Source: CCN
Type: SA34339
Red Hat update for evolution and evolution-data-server

Source: SECUNIA
Type: UNKNOWN
34339

Source: SECUNIA
Type: UNKNOWN
34363

Source: CCN
Type: SA35357
Debian update for evolution-data-server

Source: SECUNIA
Type: UNKNOWN
35357

Source: SECUNIA
Type: UNKNOWN
38915

Source: CCN
Type: ASA-2009-086
evolution-data-server security update (RHSA-2009-0354)

Source: CCN
Type: ASA-2009-087
evolution and evolution-data-server security update (RHSA-2009-0355)

Source: DEBIAN
Type: UNKNOWN
DSA-1813

Source: DEBIAN
Type: DSA-1813
evolution-data-server -- Several vulnerabilities

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2009:078

Source: REDHAT
Type: UNKNOWN
RHSA-2009:0354

Source: REDHAT
Type: UNKNOWN
RHSA-2009:0355

Source: BID
Type: UNKNOWN
33720

Source: CCN
Type: BID-33720
GNOME Evolution S/MIME Email Signature Verification Vulnerability

Source: VUPEN
Type: UNKNOWN
ADV-2010-1107

Source: CCN
Type: Red Hat Bugzilla Bug 484925
evolution: S/MIME signatures are considered to be valid even for modified messages (MITM)

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.redhat.com/show_bug.cgi?id=484925

Source: XF
Type: UNKNOWN
evolution-smime-spoofing(48666)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:9619

Source: FEDORA
Type: UNKNOWN
FEDORA-2009-2784

Source: FEDORA
Type: UNKNOWN
FEDORA-2009-2792

Source: SUSE
Type: SUSE-SR:2010:006
SUSE Security Summary Report

Source: SUSE
Type: SUSE-SR:2010:011
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:evolution:evolution:2.22.3.1:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*

  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*

  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:*

  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:5::client_workstation:*:*:*:*:*

  • Configuration RedHat 9:
  • cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20090547
    V
    CVE-2009-0547
    2022-05-20
    oval:org.opensuse.security:def:32161
    P
    Security update for cpio (Important)
    2021-08-14
    oval:org.opensuse.security:def:29389
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:29353
    P
    Security update for gdm (Important)
    2021-04-28
    oval:org.opensuse.security:def:32254
    P
    Security update for openvswitch (Important)
    2021-02-12
    oval:org.opensuse.security:def:27943
    P
    Security update for GraphicsMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33402
    P
    Security update for salt (Important)
    2020-12-01
    oval:org.opensuse.security:def:28655
    P
    Security update for dhcpcd (Important)
    2020-12-01
    oval:org.opensuse.security:def:32398
    P
    Security update for unzip (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28137
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:31941
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:28715
    P
    Security update for java-1_7_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:32610
    P
    unrar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28278
    P
    Security update for mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31953
    P
    Security update for gstreamer-0_10-plugins-base (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32698
    P
    lcms on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28514
    P
    Security update for openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27932
    P
    Security update for GraphicsMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32764
    P
    pam_mount on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28616
    P
    Security update for xorg-x11-libXext
    2020-12-01
    oval:org.opensuse.security:def:32311
    P
    Security update for quagga (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28007
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33441
    P
    Security update for evolution-data-server
    2020-12-01
    oval:org.opensuse.security:def:28671
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:32554
    P
    libltdl7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28221
    P
    Security update for libsndfile (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31942
    P
    Security update for gnome-session (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32659
    P
    expat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28362
    P
    Security update for postgresql94 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32027
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:27931
    P
    Security update for GraphicsMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32720
    P
    libnetpbm10 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28567
    P
    Security update for krb5
    2020-12-01
    oval:org.mitre.oval:def:28741
    P
    RHSA-2009:0354 -- evolution-data-server security update (Moderate)
    2015-08-17
    oval:org.mitre.oval:def:12702
    P
    DSA-1813-1 evolution-data-server -- Several vulnerabilities
    2014-06-23
    oval:org.mitre.oval:def:13406
    P
    DSA-1813-2 evolution-data-server -- Several vulnerabilities
    2014-06-23
    oval:org.mitre.oval:def:8011
    P
    DSA-1813 evolution-data-server -- Several vulnerabilities
    2014-06-23
    oval:org.mitre.oval:def:21826
    P
    ELSA-2009:0354: evolution-data-server security update (Moderate)
    2014-05-26
    oval:org.mitre.oval:def:9619
    V
    Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.
    2013-04-29
    oval:org.debian:def:1813
    V
    Several vulnerabilities
    2009-06-08
    oval:com.redhat.rhsa:def:20090354
    P
    RHSA-2009:0354: evolution-data-server security update (Moderate)
    2009-03-16
    oval:com.redhat.rhsa:def:20090355
    P
    RHSA-2009:0355: evolution and evolution-data-server security update (Moderate)
    2009-03-16
    BACK
    evolution evolution 2.22.3.1