PT-2019-12722 · Enigmail+1 · Enigmail+1

Jens Müller

·

Publicado

2019-05-21

·

Atualizado

2024-06-15

·

CVE-2019-12269

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Enigmail versions prior to 2.0.11
Description The issue allows PGP signature spoofing. For an inline PGP message, an attacker can cause the product to display a "correctly signed" message indication, but display different unauthenticated text.
Recommendations For versions prior to 2.0.11, update to version 2.0.11 or later to resolve the issue.

Exploit

Correção

Improper Verification of Cryptographic Signature

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-12269
OPENSUSE-SU-2019:1612-1
OPENSUSE-SU-2019_1612-1
OPENSUSE-SU-2024:10736-1
SUSE-SU-2019:1576-1

Produtos afetados

Enigmail
Suse