Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption is enabled and only BCC recipients are specified, which allows remote attackers to obtain sensitive information by sniffing the network.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Enigmail | Enigmail | 1.7 (including) | 1.7 (including) |
| Enigmail | Enigmail | 1.7.2 (including) | 1.7.2 (including) |
| Enigmail | Ubuntu | devel | * |
| Enigmail | Ubuntu | lucid | * |
| Enigmail | Ubuntu | precise | * |
| Enigmail | Ubuntu | trusty | * |
| Enigmail | Ubuntu | upstream | * |
| Enigmail | Ubuntu | utopic | * |