Oval Definition:oval:org.opensuse.security:def:201910732
Revision Date:2022-06-30Version:1
Title:CVE-2019-10732
Description:

In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2019-10732
SUSE CVE-2019-10732
openSUSE-SU-2021:0188-1
openSUSE-SU-2021:0227-1
Platform(s):openSUSE Leap 15.3
openSUSE Leap 15.4
openSUSE Tumbleweed
SUSE Linux Enterprise High Performance Computing 15 SP1
SUSE Linux Enterprise Server 15 SP1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Linux Enterprise Storage 6
SUSE Manager Proxy 4.0
SUSE Manager Server 4.0
SUSE Package Hub for SUSE Linux Enterprise 15 SP1
Product(s):
Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • messagelib-21.08.1-1.2 is installed
  • OR messagelib-devel-21.08.1-1.2 is installed
  • OR messagelib-lang-21.08.1-1.2 is installed
  • Definition Synopsis
  • SUSE Package Hub for SUSE Linux Enterprise 15 SP1 is installed
  • AND Package Information
  • messagelib-18.12.3-bp151.3.3.1 is installed
  • OR messagelib-devel-18.12.3-bp151.3.3.1 is installed
  • OR messagelib-lang-18.12.3-bp151.3.3.1 is installed
  • Definition Synopsis
  • openSUSE Leap 15.3 is installed
  • AND Package Information
  • messagelib-20.04.2-bp153.1.29 is installed
  • AND messagelib is signed with openSUSE key
  • OR
  • messagelib-lang-20.04.2-bp153.1.29 is installed
  • AND messagelib-lang is signed with openSUSE key
  • Definition Synopsis
  • openSUSE Leap 15.4 is installed
  • AND Package Information
  • messagelib-21.12.3-bp154.1.22 is installed
  • AND messagelib is signed with openSUSE key
  • OR
  • messagelib-lang-21.12.3-bp154.1.22 is installed
  • AND messagelib-lang is signed with openSUSE key
  • BACK