{"id":"UBUNTU-CVE-2021-3349","details":"** DISPUTED ** GNOME Evolution through 3.38.3 produces a \"Valid signature\" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior.","modified":"2021-02-01T05:15:00Z","published":"2021-02-01T05:15:00Z","withdrawn":"2025-06-23T15:53:53Z","references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-3349"},{"type":"REPORT","url":"https://dev.gnupg.org/T4735"},{"type":"REPORT","url":"https://gitlab.gnome.org/GNOME/evolution/-/issues/299"},{"type":"REPORT","url":"https://mgorny.pl/articles/evolution-uid-trust-extrapolation.html"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-3349"}],"affected":[{"package":{"name":"evolution","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/evolution"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.16.5-1ubuntu3","3.18.1-1ubuntu2","3.18.2-0ubuntu1","3.18.2-0ubuntu2","3.18.3-0ubuntu1","3.18.3-1ubuntu1","3.18.4-0ubuntu1","3.18.5-1ubuntu1","3.18.5.1-1ubuntu1","3.18.5.2-0ubuntu1","3.18.5.2-0ubuntu3","3.18.5.2-0ubuntu3.1","3.18.5.2-0ubuntu3.2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3349.json"}},{"package":{"name":"evolution","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/evolution"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.26.1-1","3.26.2-1","3.26.2-1ubuntu1","3.26.3-1","3.26.5-1","3.26.5-1build1","3.27.90-1","3.28.0-1","3.28.0-4","3.28.1-1","3.28.1-2","3.28.5-0ubuntu0.18.04.1","3.28.5-0ubuntu0.18.04.2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3349.json"}},{"package":{"name":"evolution","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/evolution"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.34.1-2","3.34.1-2build1","3.34.1-3","3.34.1-4","3.35.91-1","3.35.92-1","3.36.0-1","3.36.1-1","3.36.1-2","3.36.2-0ubuntu1","3.36.3-0ubuntu1","3.36.4-0ubuntu1","3.36.5-0ubuntu1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3349.json"}},{"package":{"name":"evolution","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/evolution"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.40.4-1","3.42.0-2","3.42.1-1","3.42.2-1","3.42.3-1","3.43.3-1","3.44.0-1","3.44.0-1ubuntu1","3.44.1-0ubuntu1","3.44.4-0ubuntu1","3.44.4-0ubuntu2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3349.json"}},{"package":{"name":"evolution","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/evolution"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.50.0-1","3.50.1-1","3.50.2-1","3.50.3-1","3.52.0-1build1","3.52.0-1build2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3349.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}