Information disclosure in Enigmail - CVE-2019-14664
Published: August 6, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
This vulnerability exists due to the insufficient validation of PGP encrypted emails. A remote attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted multipart email, trick a victim to reply to this (benign looking) email and gain unauthorized access to sensitive information on the system.
This attack variant bypasses protection mechanisms implemented after the "EFAIL" attacks.
Affected software
Fedora
thunderbird-enigmail
How to mitigate CVE-2019-14664
thunderbird-enigmail - addressed in versions 2.0.12-1.el7, 2.1.3-1.el7, 2.1.3-4.fc29, 2.1.3-4.fc30, 2.1.3-4.fc31