PT-2019-9132 · None · Enigmail

Patrick Brunschwig

·

Publicado

2019-02-11

·

Atualizado

2019-05-16

·

CVE-2018-15586

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Enigmail versions prior to 2.0.6
Description The issue allows OpenPGP signatures to be spoofed for arbitrary messages. This can be achieved by using a PGP/INLINE signature wrapped within a specially crafted multipart HTML email.
Recommendations For versions prior to 2.0.6, update to version 2.0.6 or later to resolve the issue.

Exploit

Correção

Improper Verification of Cryptographic Signature

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-15586

Produtos afetados

Enigmail