Back to search
CVE-2017-17848
Published: Dec 22, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages because a signed message part can be referenced with a cid: URI but not actually displayed. In other words, the entire containing message appears to be signed, but the recipient does not see any of the signed text.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://sourceforge.net/p/enigmail/bugs/709/
x_refsource_MISC
[debian-lts-announce] 20171223 [SECURITY] [DLA 1219-1] enigmail security update
mailing-list
x_refsource_MLIST
DSA-4070
vendor-advisory
x_refsource_DEBIAN
[oss-security] 20190430 Spoofing OpenPGP and S/MIME Signatures in Emails (multiple clients)
mailing-list
x_refsource_MLIST
20190430 OpenPGP and S/MIME signature forgery attacks in multiple email clients
mailing-list
x_refsource_FULLDISC
https://github.com/RUB-NDS/Johnny-You-Are-Fired
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now