Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption is enabled and only BCC recipients are specified, which allows remote attackers to obtain sensitive information by sniffing the network.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "2:1.7.2-0ubuntu0.14.04.1", "binary_name": "enigmail" } ] }