Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jensvoid

Researcher fromRuhr-Uni Bochum and FH Münster, Germany
#30460of 53,622
8.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2019-12017
4.3
2019-04-07
Roundcube · Roundcube Webmail · CVE-2019-10740
**Name of the Vulnerable Software and Affected Versions** Roundcube Webmail versions prior to 1.3.10 **Description** The issue allows an attacker with S/MIME or PGP encrypted emails to craft a multipart email, hiding the encrypted parts using HTML/CSS or ASCII newline characters. When the receiver replies to this email, they may unknowingly leak the plaintext of the encrypted message parts back to the attacker. **Recommendations** For versions prior to 1.3.10, update to version 1.3.10 or later to resolve the issue.
PT-2019-12018
4.3
2019-04-07
K 9 Mail · K-9 Mail · CVE-2019-10741
**Name of the Vulnerable Software and Affected Versions** K-9 Mail version 5.600 **Description** The issue allows an attacker to include the original quoted HTML code of a specially crafted email within reply messages. This can contain conditional statements that display different text when opened in a different email client. An attacker can exploit this to obtain valid S/MIME or PGP signatures for arbitrary content. **Recommendations** For K-9 Mail version 5.600, at the moment, there is no information about a newer version that contains a fix for this vulnerability.