PT-2017-15043 · Enigmail · Enigmail

Jens Müller

·

Published

2017-12-21

·

Updated

2018-02-04

·

CVE-2017-17847

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Enigmail versions prior to 1.9.9
Description An issue in Enigmail allows signature spoofing because the UI does not properly distinguish between an attachment signature and a signature that applies to the entire containing message. This can be demonstrated by an e-mail message with an attachment that is a signed e-mail message in message/rfc822 format.
Recommendations For versions prior to 1.9.9, update to version 1.9.9 or later to resolve the issue.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17847
DLA-1219-1
DSA-4070-1
MGASA-2017-0477

Affected Products

Enigmail