CVE-2017-17843

An issue was discovered in Enigmail before 1.9.9 that allows remote attackers to trigger use of an intended public key for encryption, because incorrect regular expressions are used for extraction of an e-mail address from a comma-separated list, as demonstrated by a modified Full Name field and a homograph attack, aka TBE-01-002.
Configurations

Configuration 1 (hide)

cpe:2.3:a:enigmail:enigmail:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 03:18

Type Values Removed Values Added
References () https://enigmail.net/download/other/Enigmail%20Pentest%20Report%20by%20Cure53%20-%20Excerpt.pdf - Vendor Advisory () https://enigmail.net/download/other/Enigmail%20Pentest%20Report%20by%20Cure53%20-%20Excerpt.pdf - Vendor Advisory
References () https://lists.debian.org/debian-lts-announce/2017/12/msg00021.html - () https://lists.debian.org/debian-lts-announce/2017/12/msg00021.html -
References () https://lists.debian.org/debian-security-announce/2017/msg00333.html - Third Party Advisory () https://lists.debian.org/debian-security-announce/2017/msg00333.html - Third Party Advisory
References () https://www.debian.org/security/2017/dsa-4070 - Third Party Advisory () https://www.debian.org/security/2017/dsa-4070 - Third Party Advisory
References () https://www.mail-archive.com/enigmail-users%40enigmail.net/msg04280.html - () https://www.mail-archive.com/enigmail-users%40enigmail.net/msg04280.html -

07 Nov 2023, 02:41

Type Values Removed Values Added
References
  • {'url': 'https://www.mail-archive.com/enigmail-users@enigmail.net/msg04280.html', 'name': 'https://www.mail-archive.com/enigmail-users@enigmail.net/msg04280.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'MISC'}
  • () https://www.mail-archive.com/enigmail-users%40enigmail.net/msg04280.html -

Information

Published : 2017-12-27 17:08

Updated : 2024-11-21 03:18


NVD link : CVE-2017-17843

Mitre link : CVE-2017-17843

CVE.ORG link : CVE-2017-17843


JSON object : View

Products Affected

enigmail

  • enigmail

debian

  • debian_linux