// For flags

CVE-2019-10741

 

Severity Score

4.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

K-9 Mail v5.600 can include the original quoted HTML code of a specially crafted, benign looking, email within (digitally signed) reply messages. The quoted part can contain conditional statements that show completely different text if opened in a different email client. This can be abused by an attacker to obtain valid S/MIME or PGP signatures for arbitrary content to be displayed to a third party. NOTE: the vendor states "We don't plan to take any action because of this."

K-9 Mail v5.600 puede incluir el código HTML original entrecomillado de un correo electrónico especialmente manipulado y de aspecto benigno en los mensajes de respuesta (con firma digital). La parte entrecomillada puede contener instrucciones condicionales que muestran un texto completamente distinto si se abre en un cliente de correo electrónico diferente. Un atacante podría aprovechar esto para obtener firmas S/MIME o PGP válidas para que se muestre contenido arbitrario a un tercero. NOTA: el proveedor afirma "No tenemos la intención de emprender ninguna acción por esto".

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-04-03 CVE Reserved
  • 2019-04-07 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-254: 7PK - Security Features
CAPEC
References (1)
URL Tag Source
https://github.com/k9mail/k-9/issues/3925 Third Party Advisory
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
K-9 Mail Project
Search vendor "K-9 Mail Project"
K-9 Mail
Search vendor "K-9 Mail Project" for product "K-9 Mail"
5.600
Search vendor "K-9 Mail Project" for product "K-9 Mail" and version "5.600"
android
Affected