evolution mail client GPG key selection issue

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1044741 漏洞类型
发布时间 2013-07-22 更新时间 2013-07-22
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2013070158
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
Hi,

an issue with security impact was recently fixed in Evolution. More
details can be found on the Red Hat bug report at
https://bugzilla.redhat.com/show_bug.cgi?id=973728 but it basically
boils down to a wrong selection when choosing the the keyid for a
destination email address.

Basically, when you have multiple keys in the keyrings, with overlapping
email addresses (like foo () example com and foobar () example com), you can
end up (silently) encrypting to the wrong recipient.

It actually happened to me when forwarding embargoed security issues so
it can happen in real life. Now the wrong recipient would need to
actually obtain a copy of the sent mail (since it's sent to the correct
recipient, not the wrong one), but I still think it warrants a CVE.

Quick fix was to use the documented format for email searches in GnuPG
(using <> around email addresses) but a more complete fix for explicit
key selection should appear some time in the future.

Regards,
-- 
Yves-Alexis