Heap
14-02-09, 03:40
Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0547)
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0547)