Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-10741

Опубликовано: 07 апр. 2019
Источник: nvd
CVSS3: 4.3
CVSS2: 4.3
EPSS Низкий

Описание

K-9 Mail v5.600 can include the original quoted HTML code of a specially crafted, benign looking, email within (digitally signed) reply messages. The quoted part can contain conditional statements that show completely different text if opened in a different email client. This can be abused by an attacker to obtain valid S/MIME or PGP signatures for arbitrary content to be displayed to a third party. NOTE: the vendor states "We don't plan to take any action because of this."

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:k-9_mail_project:k-9_mail:5.600:*:*:*:*:android:*:*

EPSS

Процентиль: 48%
0.0025
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-254

Связанные уязвимости

CVSS3: 4.3
github
больше 3 лет назад

K-9 Mail v5.600 can include the original quoted HTML code of a specially crafted, benign looking, email within (digitally signed) reply messages. The quoted part can contain conditional statements that show completely different text if opened in a different email client. This can be abused by an attacker to obtain valid S/MIME or PGP signatures for arbitrary content to be displayed to a third party. NOTE: the vendor states "We don't plan to take any action because of this."

EPSS

Процентиль: 48%
0.0025
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-254