Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fc79-j7vw-6xjg

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not correctly keep track of the status of multiple signatures, which allows remote attackers to spoof arbitrary email signatures via public keys containing crafted primary user ids.

The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not correctly keep track of the status of multiple signatures, which allows remote attackers to spoof arbitrary email signatures via public keys containing crafted primary user ids.

EPSS

Процентиль: 65%
0.00487
Низкий

7.5 High

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not correctly keep track of the status of multiple signatures, which allows remote attackers to spoof arbitrary email signatures via public keys containing crafted primary user ids.

CVSS3: 7.5
nvd
больше 7 лет назад

The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not correctly keep track of the status of multiple signatures, which allows remote attackers to spoof arbitrary email signatures via public keys containing crafted primary user ids.

CVSS3: 7.5
debian
больше 7 лет назад

The signature verification routine in Enigmail before 2.0.7 interprets ...

suse-cvrf
больше 7 лет назад

Security update for enigmail

suse-cvrf
больше 7 лет назад

Security update for enigmail

EPSS

Процентиль: 65%
0.00487
Низкий

7.5 High

CVSS3

Дефекты

CWE-347