CVE-2019-3890
01.08.2019, 14:15
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gnome | evolution-ews | 𝑥 < 3.31.3 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| atk |
| ||||
| atk-devel |
| ||||
| evolution |
| ||||
| evolution-bogofilter |
| ||||
| evolution-data-server |
| ||||
| evolution-data-server-devel |
| ||||
| evolution-data-server-doc |
| ||||
| evolution-data-server-langpacks |
| ||||
| evolution-data-server-perl |
| ||||
| evolution-data-server-tests |
| ||||
| evolution-devel |
| ||||
| evolution-devel-docs |
| ||||
| evolution-ews |
| ||||
| evolution-ews-langpacks |
| ||||
| evolution-help |
| ||||
| evolution-langpacks |
| ||||
| evolution-pst |
| ||||
| evolution-spamassassin |
|
Common Weakness Enumeration
References