First published: Mon Nov 12 2018(Updated: )
Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Roundcube Webmail | <1.3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Roundcube issue is CVE-2018-19205.
Roundcube before version 1.3.7 mishandles GnuPG MDC integrity-protection warnings.
The associated issue with CVE-2018-19205 is CVE-2017-17688.
The affected software for this vulnerability is Roundcube Webmail version up to and excluding 1.3.7.
CVE-2018-19205 has a severity of 7.5 (high).