An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages because a signed message part can be referenced with a cid: URI but not actually displayed. In other words, the entire containing message appears to be signed, but the recipient does not see any of the signed text.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-12-22T23:00:00
Updated: 2024-08-05T21:06:48.930Z
Reserved: 2017-12-22T00:00:00
Link: CVE-2017-17848
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-12-27T17:08:19.920
Modified: 2024-11-21T03:18:48.503
Link: CVE-2017-17848
Redhat
No data.