CVE-2018-15586: Medium severity enigmail vulnerability
Published Feb 11, 2019
·Updated
Enigmail before 2.0.6 is prone to to OpenPGP signatures being spoofed for arbitrary messages using a PGP/INLINE signature wrapped within a specially crafted multipart HTML email.
Affected Software
1 affected component
Enigmail Enigmail<2.0.6
Event History
Feb 11, 2019
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-15586.
2
What is the severity of CVE-2018-15586?
The severity of CVE-2018-15586 is medium with a CVSS score of 6.5.
3
What is the affected software for CVE-2018-15586?
The affected software for CVE-2018-15586 is Enigmail version up to 2.0.6.
4
How can an attacker exploit CVE-2018-15586?
An attacker can exploit CVE-2018-15586 by spoofing OpenPGP signatures for arbitrary messages using a specially crafted multipart HTML email.
5
Are there any references available for CVE-2018-15586?
Yes, there are references available for CVE-2018-15586. You can find them at the following links: [link1], [link2], [link3].