CVE-2017-17848

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-17848
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-17848.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-17848
Related
Published
2017-12-27T17:08:19Z
Modified
2024-11-21T03:18:48Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages because a signed message part can be referenced with a cid: URI but not actually displayed. In other words, the entire containing message appears to be signed, but the recipient does not see any of the signed text.

References

Affected packages

Debian:11 / enigmail

Package

Name
enigmail
Purl
pkg:deb/debian/enigmail?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:1.9.9-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}