Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2018-12019
Description:The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not correctly keep track of the status of multiple signatures, which allows remote attackers to spoof arbitrary email signatures via public keys containing crafted primary user ids.
Test IDs: 1.3.6.1.4.1.25623.1.0.874723   1.3.6.1.4.1.25623.1.0.874722  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2018-12019
http://seclists.org/fulldisclosure/2019/Apr/38
http://openwall.com/lists/oss-security/2018/06/13/10
http://packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.html
https://github.com/RUB-NDS/Johnny-You-Are-Fired
https://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdf
https://www.enigmail.net/index.php/en/download/changelog
http://www.openwall.com/lists/oss-security/2019/04/30/4




© 1998-2025 E-Soft Inc. All rights reserved.