Enigmail before 2.0.6 is prone to to OpenPGP signatures being spoofed for arbitrary messages using a PGP/INLINE signature wrapped within a specially crafted multipart HTML email.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-7460 Enigmail before 2.0.6 is prone to to OpenPGP signatures being spoofed for arbitrary messages using a PGP/INLINE signature wrapped within a specially crafted multipart HTML email.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T10:01:54.583Z

Reserved: 2018-08-20T00:00:00

Link: CVE-2018-15586

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-02-11T17:29:00.223

Modified: 2024-11-21T03:51:07.197

Link: CVE-2018-15586

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses