Vulnerability Name:

CVE-2019-12269 (CCN-161469)

Assigned:2019-05-21
Published:2019-05-21
Updated:2019-06-24
Summary:Enigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to display a "correctly signed" message indication, but display different unauthenticated text.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-347
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2019-12269

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2019:1612

Source: XF
Type: UNKNOWN
enigmail-cve201912269-spoofing(161469)

Source: FEDORA
Type: UNKNOWN
FEDORA-2019-941d57ed72

Source: FEDORA
Type: UNKNOWN
FEDORA-2019-45a744b873

Source: FEDORA
Type: UNKNOWN
FEDORA-2019-951d5dcaf9

Source: MISC
Type: Exploit, Third Party Advisory
https://sourceforge.net/p/enigmail/bugs/983/

Source: CCN
Type: Enigmail Web site
Enigmail 2.0.11

Source: MISC
Type: Release Notes, Vendor Advisory
https://www.enigmail.net/index.php/en/download/changelog

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2019-12269

Vulnerable Configuration:Configuration 1:
  • cpe:/a:enigmail:enigmail:*:*:*:*:*:*:*:* (Version < 2.0.11)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:654
    P
    Security update for go1.18 (Important) (in QA)
    2022-10-05
    oval:org.opensuse.security:def:201912269
    V
    CVE-2019-12269
    2022-09-02
    oval:org.opensuse.security:def:4672
    P
    Security update for the Linux Kernel (Live Patch 27 for SLE 12 SP5) (Important)
    2022-08-10
    oval:org.opensuse.security:def:4656
    P
    Security update for the Linux Kernel (Live Patch 27 for SLE 12 SP5) (Important)
    2022-07-21
    oval:org.opensuse.security:def:4636
    P
    Security update for the Linux Kernel (Live Patch 23 for SLE 12 SP5) (Important)
    2022-06-28
    oval:org.opensuse.security:def:3553
    P
    libXRes1-1.0.7-3.53 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:95183
    P
    enigmail-2.2.4-3.27.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:4628
    P
    Security update for the Linux Kernel (Important)
    2022-06-20
    oval:org.opensuse.security:def:4700
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 12 SP5) (Important)
    2022-03-01
    oval:org.opensuse.security:def:4680
    P
    Security update for the Linux Kernel (Live Patch 18 for SLE 12 SP5) (Critical)
    2022-02-16
    oval:org.opensuse.security:def:112190
    P
    enigmail-2.2.4-1.4 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:4701
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:105722
    P
    Security update for apache2 (Important) (in QA)
    2022-01-10
    oval:org.opensuse.security:def:66942
    P
    Security update for the Linux Kernel (Important)
    2021-10-12
    oval:org.opensuse.security:def:1782
    P
    Security update for ffmpeg (Moderate)
    2021-10-06
    oval:org.opensuse.security:def:70298
    P
    Security update for grilo (Important)
    2021-10-06
    oval:org.opensuse.security:def:51637
    P
    Security update for python-PyYAML (Important)
    2021-08-24
    oval:org.opensuse.security:def:63369
    P
    redis-6.0.10-1.7.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:62347
    P
    w3m-0.5.3+git20180125-1.17 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63005
    P
    dpkg-1.19.0.4-2.30 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101029
    P
    opie-32bit-2.4-1.96 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62324
    P
    sharutils-4.15.2-2.21 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62803
    P
    libnma0-1.8.24-5.2 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62323
    P
    screen-4.6.2-5.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:66850
    P
    Security update for qemu (Moderate)
    2021-06-30
    oval:org.opensuse.security:def:69500
    P
    Security update for dbus-1 (Important)
    2021-06-30
    oval:org.opensuse.security:def:51593
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) (Important)
    2021-06-18
    oval:org.opensuse.security:def:73633
    P
    Security update for python-httplib2 (Moderate)
    2021-05-31
    oval:org.opensuse.security:def:5650
    P
    Security update for xorg-x11-server (Important)
    2021-04-13
    oval:org.opensuse.security:def:51531
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:51759
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:69605
    P
    Security update for openssl-1_1 (Moderate)
    2021-03-09
    oval:org.opensuse.security:def:51487
    P
    Security update for xen (Moderate)
    2020-12-29
    oval:org.opensuse.security:def:4968
    P
    Security update for PackageKit (Low)
    2020-12-22
    oval:org.opensuse.security:def:5619
    P
    Security update for PackageKit (Low)
    2020-12-22
    oval:org.opensuse.security:def:5606
    P
    Security update for curl (Moderate)
    2020-12-09
    oval:org.opensuse.security:def:63613
    P
    enigmail-2.1.5-3.22.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117210
    P
    enigmail-2.1.5-3.22.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107695
    P
    enigmail-2.1.5-3.22.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:94316
    P
    enigmail-2.1.5-3.22.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62524
    P
    gnome-shell-3.26.2+20180130.0d9c74212-4.16.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2524
    P
    enigmail-2.1.5-3.22.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63143
    P
    apache2-mod_security2-2.9.2-1.34 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:4897
    P
    Security update for dpdk (Critical)
    2020-12-02
    oval:org.opensuse.security:def:4780
    P
    Security update for postgresql10 (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4954
    P
    Security update for python3 (Important)
    2020-12-02
    oval:org.opensuse.security:def:4981
    P
    Security update for php7 (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4924
    P
    Security update for freetds (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4745
    P
    Initial update for kernel-azure (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4824
    P
    Security update for libvirt (Important)
    2020-12-02
    oval:org.opensuse.security:def:4761
    P
    Security update for postgresql10 (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4878
    P
    Security update for mozilla-nspr, mozilla-nss (Important)
    2020-12-02
    oval:org.opensuse.security:def:5575
    P
    Security update for Mozilla Thunderbird (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4917
    P
    Security update for ovmf (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4805
    P
    Security update for xen (Important)
    2020-12-02
    oval:org.opensuse.security:def:4746
    P
    Security update for xen (Important)
    2020-12-02
    oval:org.opensuse.security:def:4922
    P
    Security update for postgresql10 (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4853
    P
    Security update for rsyslog (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4961
    P
    Security update for nodejs8 (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4910
    P
    Security update for postgresql10 (Important)
    2020-12-02
    oval:org.opensuse.security:def:51079
    P
    Security update for python-setuptools (Important)
    2020-12-02
    oval:org.opensuse.security:def:4937
    P
    Security update for postgresql10 (Important)
    2020-12-02
    oval:org.opensuse.security:def:4790
    P
    Security update for util-linux and shadow (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:25066
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:74132
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:52393
    P
    Security update for freerdp (Important)
    2020-12-01
    oval:org.opensuse.security:def:25331
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:52313
    P
    Security update for nghttp2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51123
    P
    Security update for bluez (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25618
    P
    Security update for python3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:50941
    P
    Security update for python-rtslib-fb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63696
    P
    Security update for libtasn1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53824
    P
    Security update for enigmail (Important)
    2020-12-01
    oval:org.opensuse.security:def:25706
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:72958
    P
    Security update for enigmail (Important)
    2020-12-01
    oval:org.opensuse.security:def:52194
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:53706
    P
    Security update for rmt-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:52042
    P
    Security update for gcc9 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:72840
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:25002
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64192
    P
    ctdb on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52357
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25274
    P
    Security update for djvulibre (Low)
    2020-12-01
    oval:org.opensuse.security:def:52241
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:50985
    P
    Security update for libproxy (Important)
    2020-12-01
    oval:org.opensuse.security:def:25565
    P
    Security update for SUSE Manager Client Tools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52430
    P
    Security update for clamav-database (Important)
    2020-12-01
    oval:org.opensuse.security:def:50919
    P
    Security update for vim (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66269
    P
    Security update for enigmail (Important)
    2020-12-01
    oval:org.opensuse.security:def:51316
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:63936
    P
    Security update for dpdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:53750
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:52086
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:73515
    P
    nasm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25764
    P
    Security update for webkitgtk (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50918
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64080
    P
    Security update for perl-DBI (Important)
    2020-12-01
    oval:org.opensuse.security:def:50223
    P
    enigmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52285
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:70193
    P
    perl-doc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25193
    P
    Security update for ed (Low)
    2020-12-01
    oval:org.opensuse.security:def:52474
    P
    Security update for the Linux Kernel (Critical)
    2020-12-01
    oval:org.opensuse.security:def:50963
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25415
    P
    Security update for openldap2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:52349
    P
    Security update for libEMF (Important)
    2020-12-01
    oval:org.opensuse.security:def:24991
    P
    Security update for java-1_7_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:26437
    P
    Security update for enigmail (Important)
    2020-12-01
    oval:org.opensuse.security:def:51360
    P
    Security update for git (Important)
    2020-12-01
    oval:org.opensuse.security:def:66177
    P
    Security update for ipmitool (Important)
    2020-12-01
    oval:org.opensuse.security:def:63830
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:26402
    P
    Security update for irssi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51803
    P
    Security update for ceph (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50962
    P
    Security update for libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25720
    P
    Security update for tomcat (Important)
    2020-12-01
    oval:org.opensuse.security:def:53780
    P
    Security update for enigmail (Important)
    2020-12-01
    oval:org.opensuse.security:def:64038
    P
    Security update for mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:74258
    P
    Security update for enigmail (Important)
    2020-12-01
    oval:org.opensuse.security:def:52150
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50169
    P
    pidgin-plugin-otr on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:99836
    P
    (Moderate)
    2019-11-25
    oval:org.opensuse.security:def:109882
    P
    Security update for enigmail (Important)
    2019-06-24
    oval:org.opensuse.security:def:93345
    P
    Security update for enigmail (Important)
    2019-06-20
    oval:com.ubuntu.cosmic:def:2019122690000000
    V
    CVE-2019-12269 on Ubuntu 18.10 (cosmic) - low.
    2019-05-21
    oval:com.ubuntu.disco:def:2019122690000000
    V
    CVE-2019-12269 on Ubuntu 19.04 (disco) - low.
    2019-05-21
    oval:com.ubuntu.bionic:def:2019122690000000
    V
    CVE-2019-12269 on Ubuntu 18.04 LTS (bionic) - low.
    2019-05-21
    oval:com.ubuntu.xenial:def:2019122690000000
    V
    CVE-2019-12269 on Ubuntu 16.04 LTS (xenial) - low.
    2019-05-21
    BACK
    enigmail enigmail *