Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Gnome Evolution GnuPG 任意内容注入漏洞
Vulnerability Description
当调用GnuPG时,Evolution 2.8.1及之前版本没有正确的使用--status-fd自变量,这会导致带有多组件的OpenPGP信息的署名部分和非署名部分很难被区分。远程攻击者可以在不接受检测的情况下,伪造信息内容。
CVSS Information
N/A
Vulnerability Type
N/A