USN-1922-1: Evolution Data Server vulnerability

Ubuntu Security Notice USN-1922-1

31st July, 2013

evolution-data-server vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 13.04
  • Ubuntu 12.10
  • Ubuntu 12.04 LTS

Summary

Evolution would sometimes encrypt email to the wrong recipient.

Software description

  • evolution-data-server - Evolution suite data server

Details

Yves-Alexis Perez discovered that Evolution Data Server did not properly
select GPG recipients. Under certain circumstances, this could result in
Evolution encrypting email to an unintended recipient.

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 13.04:
libcamel-1.2-40 3.6.4-0ubuntu1.1
Ubuntu 12.10:
libcamel-1.2-40 3.6.2-0ubuntu0.2
Ubuntu 12.04 LTS:
libcamel-1.2-29 3.2.3-0ubuntu7.1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to restart Evolution to make all
the necessary changes.

References

CVE-2013-4166