Improper Verification of Cryptographic Signature in Enigmail - CVE-2017-17848

 

Improper Verification of Cryptographic Signature in Enigmail - CVE-2017-17848

Published: December 27, 2017 / Updated: July 17, 2020


Vulnerability identifier: #VU31380
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-17848
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages because a signed message part can be referenced with a cid: URI but not actually displayed. In other words, the entire containing message appears to be signed, but the recipient does not see any of the signed text.


Affected software

Enigmail

How to mitigate CVE-2017-17848

Install update from vendor's website.

Enigmail - update to 1.9.9

External References

Related Security Bulletins