SUSE-SU-2018:2641-1

Source
https://www.suse.com/support/update/announcement/2018/suse-su-20182641-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:2641-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2018:2641-1
Published
2018-09-06T17:41:23Z
Modified
2018-09-06T17:41:23Z
Summary
Security update for enigmail
Details

This update for enigmail to 2.0.8 fixes the following issues:

The enigmail 2.0.8 release addresses a security issue and solves a few regression bugs.

  • A security issue has been fixed that allows an attacker to prepare a plain, unauthenticated HTML message in a way that it looks like it's signed and/or encrypted (boo#1104036)
References

Affected packages

SUSE:Linux Enterprise Workstation Extension 15 / enigmail

Package

Name
enigmail
Purl
pkg:rpm/suse/enigmail&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.8-3.10.1

Ecosystem specific

{
    "binaries": [
        {
            "enigmail": "2.0.8-3.10.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:2641-1.json"