CVE-2017-17845 PUBLISHED

An issue was discovered in Enigmail before 1.9.9. Improper Random Secret Generation occurs because Math.Random() is used by pretty Easy privacy (pEp), aka TBE-01-001.

EPSS 0.51% · 66.1th percentile

Risk Scores

EPSS Score
0.51%
66.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSenigmail0, 2:1.8.2-0ubuntu1, 2:1.8.2-4fakesync1
Ubuntu:14.04:LTSenigmail0, 2:1.9.7-0ubuntu0.14.04.1, 2:1.5.2-0ubuntu1

Timeline

References

Open in Interactive Console →