CVE-2018-19205: Infoleak
Published Nov 12, 2018
·Updated
Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigmadrivergnupg.php.
Affected Software
1 affected component
Roundcube Webmail<1.3.7
Event History
Nov 12, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Roundcube issue?
The vulnerability ID for this Roundcube issue is CVE-2018-19205.
2
What does Roundcube before version 1.3.7 mishandle?
Roundcube before version 1.3.7 mishandles GnuPG MDC integrity-protection warnings.
3
What is the associated issue with CVE-2018-19205?
The associated issue with CVE-2018-19205 is CVE-2017-17688.
4
What is the affected software for this vulnerability?
The affected software for this vulnerability is Roundcube Webmail version up to and excluding 1.3.7.
5
How severe is CVE-2018-19205?
CVE-2018-19205 has a severity of 7.5 (high).