CVE Vulnerabilities

CVE-2017-17847

Improper Verification of Cryptographic Signature

Published: Dec 27, 2017 | Modified: Apr 20, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI does not properly distinguish between an attachment signature, and a signature that applies to the entire containing message, aka TBE-01-021. This is demonstrated by an e-mail message with an attachment that is a signed e-mail message in message/rfc822 format.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

NameVendorStart VersionEnd Version
EnigmailEnigmail*1.9.9 (excluding)
EnigmailUbuntuartful*
EnigmailUbuntuesm-apps/xenial*
EnigmailUbuntutrusty*
EnigmailUbuntuupstream*
EnigmailUbuntuxenial*
EnigmailUbuntuzesty*

References