CVE-2018-12019
Summary
| CVE | CVE-2018-12019 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-13 23:29:00 UTC |
| Updated | 2019-05-16 18:29:00 UTC |
| Description | The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not correctly keep track of the status of multiple signatures, which allows remote attackers to spoof arbitrary email signatures via public keys containing crafted primary user ids. |
Risk And Classification
Problem Types: CWE-347
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Enigmail - Changelog | MISC | www.enigmail.net | Exploit, Vendor Advisory |
| Johnny-You-Are-Fired/johnny-fired.pdf at master · RUB-NDS/Johnny-You-Are-Fired · GitHub | MISC | github.com | |
| GitHub - RUB-NDS/Johnny-You-Are-Fired: Artifacts for the USENIX publication. | MISC | github.com | |
| oss-security - Spoofing OpenPGP and S/MIME Signatures in Emails (multiple clients) | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| Johnny You Are Fired ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| Full Disclosure: OpenPGP and S/MIME signature forgery attacks in multiple email clients | FULLDISC | seclists.org | Mailing List, Third Party Advisory |
| oss-security - CVE-2018-12020, CVE-2018-12019 in GnuPG, Enigmails, GPGTools, python-gnupg | MISC | openwall.com | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.