Vulnerability Name: | CVE-2017-17843 (CCN-136693) | ||||||||||||||||||||
Assigned: | 2017-12-22 | ||||||||||||||||||||
Published: | 2017-12-22 | ||||||||||||||||||||
Updated: | 2019-10-03 | ||||||||||||||||||||
Summary: | An issue was discovered in Enigmail before 1.9.9 that allows remote attackers to trigger use of an intended public key for encryption, because incorrect regular expressions are used for extraction of an e-mail address from a comma-separated list, as demonstrated by a modified Full Name field and a homograph attack, aka TBE-01-002. | ||||||||||||||||||||
CVSS v3 Severity: | 5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-17843 Source: MISC Type: Vendor Advisory https://enigmail.net/download/other/Enigmail%20Pentest%20Report%20by%20Cure53%20-%20Excerpt.pdf Source: XF Type: UNKNOWN enigmail-cve201717843-weak-security(136693) Source: MLIST Type: UNKNOWN [debian-lts-announce] 20171223 [SECURITY] [DLA 1219-1] enigmail security update Source: MISC Type: Third Party Advisory https://lists.debian.org/debian-security-announce/2017/msg00333.html Source: CCN Type: Debian Security Advisory: DSA-4070-1 enigmail -- security update Source: DEBIAN Type: Third Party Advisory DSA-4070 Source: CCN Type: Enigmail Web site A simple interface for OpenPGP email security Source: MISC Type: Mailing List, Third Party Advisory https://www.mail-archive.com/enigmail-users@enigmail.net/msg04280.html Source: CCN Type: WhiteSource Vulnerability Database CVE-2017-17843 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |