Search CVE reports
1 – 10 of 16 results
CVE-2019-14664
Medium priorityIn Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This...
1 affected packages
enigmail
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
enigmail | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2019-12269
Low priorityEnigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to display a "correctly signed" message indication, but display different unauthenticated text.
1 affected packages
enigmail
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
enigmail | Not in release | Not affected | Not affected | Vulnerable | Vulnerable |
CVE-2018-15586
Medium priorityEnigmail before 2.0.6 is prone to to OpenPGP signatures being spoofed for arbitrary messages using a PGP/INLINE signature wrapped within a specially crafted multipart HTML email.
1 affected packages
enigmail
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
enigmail | — | — | — | Not affected | Not affected |
CVE-2018-12019
Medium priorityThe signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not correctly keep track of the status of multiple signatures, which allows remote attackers to spoof arbitrary...
1 affected packages
enigmail
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
enigmail | Not in release | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
CVE-2018-12020
Medium prioritySome fixes available 23 of 40
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the...
5 affected packages
enigmail, gnupg, gnupg1, gnupg2, python-gnupg
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
enigmail | Not in release | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
gnupg | Not in release | Not in release | Not in release | Not in release | Fixed |
gnupg1 | Not affected | Not affected | Not affected | Vulnerable | Not in release |
gnupg2 | Fixed | Fixed | Fixed | Fixed | Fixed |
python-gnupg | Not affected | Not affected | Not affected | Fixed | Fixed |
CVE-2017-17688
Medium priority** DISPUTED ** The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in...
1 affected packages
enigmail
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
enigmail | — | — | — | Not affected | Not affected |
CVE-2017-17848
High prioritySome fixes available 3 of 4
An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages because a signed message part can be referenced with a cid: URI but not actually...
1 affected packages
enigmail
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
enigmail | — | — | — | — | Fixed |
CVE-2017-17847
High prioritySome fixes available 3 of 4
An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI does not properly distinguish between an attachment signature, and a signature that applies to the entire containing message, aka...
1 affected packages
enigmail
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
enigmail | — | — | — | — | Fixed |
CVE-2017-17846
Low prioritySome fixes available 3 of 4
An issue was discovered in Enigmail before 1.9.9. Regular expressions are exploitable for Denial of Service, because of attempts to match arbitrarily long strings, aka TBE-01-003.
1 affected packages
enigmail
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
enigmail | — | — | — | — | Fixed |
CVE-2017-17845
Low prioritySome fixes available 3 of 4
An issue was discovered in Enigmail before 1.9.9. Improper Random Secret Generation occurs because Math.Random() is used by pretty Easy privacy (pEp), aka TBE-01-001.
1 affected packages
enigmail
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
enigmail | — | — | — | — | Fixed |