SB2017122704 - Input validation error in enigmail.mozdev Enigmail



SB2017122704 - Input validation error in enigmail.mozdev Enigmail

Published: December 27, 2017 Updated: August 8, 2020

Security Bulletin ID SB2017122704
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Input validation error (CVE-ID: CVE-2017-17843)

The vulnerability allows a remote non-authenticated attacker to manipulate data.

An issue was discovered in Enigmail before 1.9.9 that allows remote attackers to trigger use of an intended public key for encryption, because incorrect regular expressions are used for extraction of an e-mail address from a comma-separated list, as demonstrated by a modified Full Name field and a homograph attack, aka TBE-01-002.


Remediation

Install update from vendor's website.