CVE-2017-17848: High severity enigmail vulnerability
Published Dec 22, 2017
·Updated
An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages because a signed message part can be referenced with a cid: URI but not actually displayed. In other words, the entire containing message appears to be signed, but the recipient does not see any of the signed text.
Affected Software
5 affected componentsFixes available
debian/enigmail
2:2.2.4-0.2~deb10u12:2.1.3+ds1-4~deb10u22:2.2.4-0.3
Enigmail Enigmail<1.9.9
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Dec 22, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17848?
CVE-2017-17848 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-17848?
The fix for CVE-2017-17848 is to upgrade Enigmail to version 1.9.9 or later.
3
What type of attack does CVE-2017-17848 allow?
CVE-2017-17848 allows for signature spoofing in multipart/related messages.
4
Which versions of Enigmail are affected by CVE-2017-17848?
All versions of Enigmail prior to 1.9.9 are affected by CVE-2017-17848.
5
Is CVE-2017-17848 specific to any operating system?
CVE-2017-17848 is particularly relevant to Debian operating systems.