Information disclosure in Enigmail - CVE-2019-14664

 

Information disclosure in Enigmail - CVE-2019-14664

Published: August 6, 2019


Vulnerability identifier: #VU19940
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14664
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

This vulnerability exists due to the insufficient validation of PGP encrypted emails. A remote attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted multipart email, trick a victim to reply to this (benign looking) email and gain unauthorized access to sensitive information on the system.

This attack variant bypasses protection mechanisms implemented after the "EFAIL" attacks.


Affected software

Enigmail
Fedora
thunderbird-enigmail

How to mitigate CVE-2019-14664

Install updates from vendor's website.

Enigmail - update to 2.1
thunderbird-enigmail - addressed in versions 2.0.12-1.el7, 2.1.3-1.el7, 2.1.3-4.fc29, 2.1.3-4.fc30, 2.1.3-4.fc31

External References

Related Security Bulletins