Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-17843

Опубликовано: 27 дек. 2017
Источник: ubuntu
Приоритет: high
CVSS2: 4.3
CVSS3: 5.9

Описание

An issue was discovered in Enigmail before 1.9.9 that allows remote attackers to trigger use of an intended public key for encryption, because incorrect regular expressions are used for extraction of an e-mail address from a comma-separated list, as demonstrated by a modified Full Name field and a homograph attack, aka TBE-01-002.

РелизСтатусПримечание
artful

released

2:1.9.9-0ubuntu0.17.10.1
devel

not-affected

2:1.9.9-1
esm-apps/xenial

released

2:1.9.9-0ubuntu0.16.04.1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [2:1.9.9-0ubuntu0.14.04.1]]
precise/esm

DNE

trusty

released

2:1.9.9-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [2:1.9.9-0ubuntu0.14.04.1]
upstream

released

2:1.9.9-1
xenial

released

2:1.9.9-0ubuntu0.16.04.1
zesty

ignored

end of life

Показывать по

4.3 Medium

CVSS2

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
около 8 лет назад

An issue was discovered in Enigmail before 1.9.9 that allows remote attackers to trigger use of an intended public key for encryption, because incorrect regular expressions are used for extraction of an e-mail address from a comma-separated list, as demonstrated by a modified Full Name field and a homograph attack, aka TBE-01-002.

CVSS3: 5.9
debian
около 8 лет назад

An issue was discovered in Enigmail before 1.9.9 that allows remote at ...

CVSS3: 5.9
github
больше 3 лет назад

An issue was discovered in Enigmail before 1.9.9 that allows remote attackers to trigger use of an intended public key for encryption, because incorrect regular expressions are used for extraction of an e-mail address from a comma-separated list, as demonstrated by a modified Full Name field and a homograph attack, aka TBE-01-002.

4.3 Medium

CVSS2

5.9 Medium

CVSS3