Описание
Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption is enabled and only BCC recipients are specified, which allows remote attackers to obtain sensitive information by sniffing the network.
Ссылки
- Patch
- Exploit
- Patch
- Exploit
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:enigmail:enigmail:1.7:*:*:*:*:*:*:*
cpe:2.3:a:enigmail:enigmail:1.7.2:*:*:*:*:*:*:*
EPSS
Процентиль: 79%
0.01938
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-310
Связанные уязвимости
ubuntu
около 12 лет назад
Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption is enabled and only BCC recipients are specified, which allows remote attackers to obtain sensitive information by sniffing the network.
debian
около 12 лет назад
Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption ...
github
больше 4 лет назад
Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption is enabled and only BCC recipients are specified, which allows remote attackers to obtain sensitive information by sniffing the network.
EPSS
Процентиль: 79%
0.01938
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-310