PT-2019-20198 · None+2 · Enigmail+2

Publicado

2019-11-15

·

Atualizado

2019-11-15

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Name of the Vulnerable Software and Affected Versions enigmail versions prior to 2.1.2 enimail versions prior to 2.0.12
Description The issue is related to the SKS Keyserver Network Attack. To mitigate this, the default keyserver has been set to keys.openpgp.org in enimail version 2.0.12. Enigmail has been updated to version 2.1.2, which includes compatibility with Mozilla Thunderbird 68, a new simplified setup wizard, full support for keys.openpgp.org, default to ECC keys on GnuPG 2.1 or later, and Autocrypt implementation with key-gossip and updates to known keys.
Recommendations For enigmail versions prior to 2.1.2, update to version 2.1.2 to fix the issue. For enimail versions prior to 2.0.12, update to version 2.0.12 to mitigate the SKS Keyserver Network Attack.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

SUSE-SU-2019:2982-1

Produtos afetados

Enigmail
Gnupg
Thunderbird