CVE-2019-12269: High severity enigmail vulnerability
Published May 21, 2019
·Updated
Enigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to display a "correctly signed" message indication, but display different unauthenticated text.
Affected Software
1 affected component
Enigmail Enigmail<2.0.11
Event History
May 21, 2019
CVE Published
via MITRE·07:50 PM
Data Sourced
via MITRE·07:50 PM
Description
Frequently Asked Questions
1
What is CVE-2019-12269?
CVE-2019-12269 is a vulnerability in Enigmail before version 2.0.11 that allows PGP signature spoofing.
2
How does CVE-2019-12269 work?
For an inline PGP message, an attacker can cause Enigmail to display a "correctly signed" message indication, but display different unauthenticated text.
3
What is the severity of CVE-2019-12269?
CVE-2019-12269 has a severity level of high, with a CVSS score of 7.5.
4
Which software versions are affected by CVE-2019-12269?
Enigmail versions up to and exclusive of 2.0.11 are affected by CVE-2019-12269.
5
How can CVE-2019-12269 be fixed?
Upgrade Enigmail to version 2.0.11 or later to fix CVE-2019-12269.