CVE-2017-17843
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Enigmail before 1.9.9 that allows remote attackers to trigger use of an intended public key for encryption, because incorrect regular expressions are used for extraction of an e-mail address from a comma-separated list, as demonstrated by a modified Full Name field and a homograph attack, aka TBE-01-002.
Se ha descubierto un problema en Enigmail, en versiones anteriores a la 1.9.9, que permite que atacantes remotos activen el uso de una clave pública planeada para el cifrado, debido a que se utilizan expresiones regulares incorrectas para la extracción de una dirección de email de una lista separada por comas. Esto se ha demostrado por el campo Full Name modificado y un ataque homógrafo, también conocido como TBE-01-002.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-22 CVE Reserved
- 2017-12-22 CVE Published
- 2023-07-18 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2017/12/msg00021.html | Mailing List | |
https://lists.debian.org/debian-security-announce/2017/msg00333.html | Third Party Advisory | |
https://www.mail-archive.com/enigmail-users%40enigmail.net/msg04280.html | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://enigmail.net/download/other/Enigmail%20Pentest%20Report%20by%20Cure53%20-%20Excerpt.pdf | 2023-11-07 | |
https://www.debian.org/security/2017/dsa-4070 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Enigmail Search vendor "Enigmail" | Enigmail Search vendor "Enigmail" for product "Enigmail" | < 1.9.9 Search vendor "Enigmail" for product "Enigmail" and version " < 1.9.9" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|