VDB
DEBIAN-CVE-2017-17843
DEBIAN-CVE-2017-17843
PUBLISHED
CVSS 5.900000095367432 MEDIUM
An issue was discovered in Enigmail before 1.9.9 that allows remote attackers to trigger use of an intended public key for encryption, because incorrect regular expressions are used for extraction of an e-mail address from a comma-separated list, as demonstrated by a modified Full Name field and a homograph attack, aka TBE-01-002.
Risk Scores
CVSS v3.0
5.900000095367432
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | enigmail | 0, 0, 0 |
Timeline
- Dec 27, 2017 CVE Published
- Apr 28, 2026 CVE Updated