CVE-2017-17848
Johnny You Are Fired
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages because a signed message part can be referenced with a cid: URI but not actually displayed. In other words, the entire containing message appears to be signed, but the recipient does not see any of the signed text.
Se ha descubierto un problema en versiones anteriores a la 1.9.9 de Enigmail. En una variante de CVE-2017-17847, se puede dar la suplantaciĆ³n de firma para mensajes multipart/related debido a que se puede hacer referencia a una parte del mensaje firmado con un id de contenido cid: URI, pero no se puede mostrar. En otras palabras, todo el contenido del mensaje aparece como firmado, pero el destinatario no visualiza nada del texto firmado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-22 CVE Reserved
- 2017-12-22 CVE Published
- 2024-02-17 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-347: Improper Verification of Cryptographic Signature
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.html | Third Party Advisory | |
http://seclists.org/fulldisclosure/2019/Apr/38 | Mailing List | |
http://www.openwall.com/lists/oss-security/2019/04/30/4 | Mailing List | |
https://github.com/RUB-NDS/Johnny-You-Are-Fired | X_refsource_misc | |
https://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdf | X_refsource_misc | |
https://lists.debian.org/debian-lts-announce/2017/12/msg00021.html | Mailing List | |
https://lists.debian.org/debian-security-announce/2017/msg00333.html | Mailing List | |
https://sourceforge.net/p/enigmail/bugs/709 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.debian.org/security/2017/dsa-4070 | 2019-05-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Enigmail Search vendor "Enigmail" | Enigmail Search vendor "Enigmail" for product "Enigmail" | < 1.9.9 Search vendor "Enigmail" for product "Enigmail" and version " < 1.9.9" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 7.0 Search vendor "Debian" for product "Debian Linux" and version "7.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|