CVE-2014-5369: Medium severity enigmail vulnerability
Published Sep 8, 2014
·Updated
Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption is enabled and only BCC recipients are specified, which allows remote attackers to obtain sensitive information by sniffing the network.
Affected Software
2 affected components
Enigmail Enigmail=1.7
Enigmail Enigmail=1.7.2
Remediation
Patch Available
Event History
Sep 8, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5369?
CVE-2014-5369 has a medium severity rating due to its potential to expose sensitive information.
2
How do I fix CVE-2014-5369?
To fix CVE-2014-5369, update Enigmail to version 1.7.2 or later.
3
What are the risks associated with CVE-2014-5369?
The risks associated with CVE-2014-5369 include the possibility of remote attackers obtaining sensitive email content by listening to network traffic.
4
Which versions of Enigmail are affected by CVE-2014-5369?
Enigmail versions 1.7.x prior to 1.7.2 are affected by CVE-2014-5369.
5
Is there a workaround for CVE-2014-5369?
A workaround for CVE-2014-5369 is to avoid sending emails with only BCC recipients while encryption is enabled until the software can be updated.