CVE-2017-17848 PUBLISHED

An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages because a signed message part can be referenced with a cid: URI but not actually displayed. In other words, the entire containing message appears to be signed, but the recipient does not see any of the signed text.

EPSS 0.87% · 75.1th percentile

Risk Scores

EPSS Score
0.87%
75.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSenigmail0, 2:1.8.2-4fakesync1, 2:1.9.1-1
Ubuntu:14.04:LTSenigmail0, *, 2:1.5.2-0ubuntu1

Timeline

References

Open in Interactive Console →