CVE Vulnerabilities

CVE-2019-12269

Improper Verification of Cryptographic Signature

Published: May 21, 2019 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

Enigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to display a correctly signed message indication, but display different unauthenticated text.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Enigmail Enigmail * 2.0.11 (excluding)
Enigmail Ubuntu bionic *
Enigmail Ubuntu cosmic *
Enigmail Ubuntu disco *
Enigmail Ubuntu esm-apps/bionic *
Enigmail Ubuntu esm-apps/xenial *
Enigmail Ubuntu trusty *
Enigmail Ubuntu xenial *

References