Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

1 – 10 of 16 results


CVE-2019-14664

Medium priority
Needs evaluation

In Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This...

1 affected packages

enigmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
enigmail Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2019-12269

Low priority
Vulnerable

Enigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to display a "correctly signed" message indication, but display different unauthenticated text.

1 affected packages

enigmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
enigmail Not in release Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2018-15586

Medium priority
Not affected

Enigmail before 2.0.6 is prone to to OpenPGP signatures being spoofed for arbitrary messages using a PGP/INLINE signature wrapped within a specially crafted multipart HTML email.

1 affected packages

enigmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
enigmail Not affected Not affected
Show less packages

CVE-2018-12019

Medium priority
Vulnerable

The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not correctly keep track of the status of multiple signatures, which allows remote attackers to spoof arbitrary...

1 affected packages

enigmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
enigmail Not in release Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2018-12020

Medium priority

Some fixes available 23 of 40

mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the...

5 affected packages

enigmail, gnupg, gnupg1, gnupg2, python-gnupg

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
enigmail Not in release Vulnerable Vulnerable Vulnerable Vulnerable
gnupg Not in release Not in release Not in release Not in release Fixed
gnupg1 Not affected Not affected Not affected Vulnerable Not in release
gnupg2 Fixed Fixed Fixed Fixed Fixed
python-gnupg Not affected Not affected Not affected Fixed Fixed
Show less packages

CVE-2017-17688

Medium priority
Ignored

** DISPUTED ** The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in...

1 affected packages

enigmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
enigmail Not affected Not affected
Show less packages

CVE-2017-17848

High priority

Some fixes available 3 of 4

An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages because a signed message part can be referenced with a cid: URI but not actually...

1 affected packages

enigmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
enigmail Fixed
Show less packages

CVE-2017-17847

High priority

Some fixes available 3 of 4

An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI does not properly distinguish between an attachment signature, and a signature that applies to the entire containing message, aka...

1 affected packages

enigmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
enigmail Fixed
Show less packages

CVE-2017-17846

Low priority

Some fixes available 3 of 4

An issue was discovered in Enigmail before 1.9.9. Regular expressions are exploitable for Denial of Service, because of attempts to match arbitrarily long strings, aka TBE-01-003.

1 affected packages

enigmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
enigmail Fixed
Show less packages

CVE-2017-17845

Low priority

Some fixes available 3 of 4

An issue was discovered in Enigmail before 1.9.9. Improper Random Secret Generation occurs because Math.Random() is used by pretty Easy privacy (pEp), aka TBE-01-001.

1 affected packages

enigmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
enigmail Fixed
Show less packages