CVE Vulnerabilities

CVE-2017-17847

Improper Verification of Cryptographic Signature

Published: Dec 27, 2017 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
HIGH

An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI does not properly distinguish between an attachment signature, and a signature that applies to the entire containing message, aka TBE-01-021. This is demonstrated by an e-mail message with an attachment that is a signed e-mail message in message/rfc822 format.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Enigmail Enigmail * 1.9.9 (excluding)
Enigmail Ubuntu artful *
Enigmail Ubuntu trusty *
Enigmail Ubuntu upstream *
Enigmail Ubuntu xenial *
Enigmail Ubuntu zesty *

References