Enigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to display a "correctly signed" message indication, but display different unauthenticated text.
References
Configurations
Information
Published : 2019-05-21 13:29
Updated : 2019-06-24 11:15
NVD link : CVE-2019-12269
Mitre link : CVE-2019-12269
JSON object : View
CWE
CWE-347
Improper Verification of Cryptographic Signature
Products Affected
enigmail
- enigmail