Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption is enabled and only BCC recipients are specified, which allows remote attackers to obtain sensitive information by sniffing the network.
{ "binaries": [ { "binary_version": "2:1.7.2-0ubuntu0.14.04.1", "binary_name": "enigmail" } ], "availability": "No subscription required" }