In Claws Mail 3.14.1, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.
{ "binaries": [ { "binary_name": "claws-mail", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-acpi-notifier", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-address-keeper", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-archiver-plugin", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-attach-remover", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-attach-warner", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-bogofilter", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-bsfilter-plugin", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-clamd-plugin", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-extra-plugins", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-fancy-plugin", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-feeds-reader", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-fetchinfo-plugin", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-gdata-plugin", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-i18n", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-libravatar", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-mailmbox-plugin", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-managesieve", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-multi-notifier", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-newmail-plugin", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-pdf-viewer", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-perl-filter", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-pgpinline", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-pgpmime", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-plugins", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-python-plugin", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-smime-plugin", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-spam-report", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-spamassassin", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-tnef-parser", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-tools", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "claws-mail-vcalendar-plugin", "binary_version": "3.13.2-1ubuntu1" }, { "binary_name": "libclaws-mail-dev", "binary_version": "3.13.2-1ubuntu1" } ] }
{ "binaries": [ { "binary_name": "claws-mail", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-acpi-notifier", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-address-keeper", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-archiver-plugin", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-attach-remover", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-attach-warner", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-bogofilter", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-bsfilter-plugin", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-clamd-plugin", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-extra-plugins", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-feeds-reader", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-fetchinfo-plugin", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-gdata-plugin", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-i18n", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-libravatar", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-mailmbox-plugin", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-managesieve", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-multi-notifier", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-newmail-plugin", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-pdf-viewer", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-perl-filter", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-pgpinline", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-pgpmime", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-plugins", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-python-plugin", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-smime-plugin", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-spam-report", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-spamassassin", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-tnef-parser", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-tools", "binary_version": "3.16.0-1" }, { "binary_name": "claws-mail-vcalendar-plugin", "binary_version": "3.16.0-1" }, { "binary_name": "libclaws-mail-dev", "binary_version": "3.16.0-1" } ] }
{ "binaries": [ { "binary_name": "claws-mail", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-acpi-notifier", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-address-keeper", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-archiver-plugin", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-attach-remover", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-attach-warner", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-bogofilter", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-bsfilter-plugin", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-clamd-plugin", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-dillo-viewer", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-extra-plugins", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-feeds-reader", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-fetchinfo-plugin", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-gdata-plugin", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-i18n", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-libravatar", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-litehtml-viewer", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-mailmbox-plugin", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-managesieve", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-multi-notifier", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-newmail-plugin", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-pdf-viewer", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-perl-filter", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-pgpinline", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-pgpmime", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-plugins", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-smime-plugin", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-spam-report", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-spamassassin", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-tnef-parser", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-tools", "binary_version": "3.17.5-2" }, { "binary_name": "claws-mail-vcalendar-plugin", "binary_version": "3.17.5-2" }, { "binary_name": "libclaws-mail-dev", "binary_version": "3.17.5-2" } ] }
{ "binaries": [ { "binary_name": "claws-mail", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-acpi-notifier", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-address-keeper", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-archiver-plugin", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-attach-remover", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-attach-warner", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-bogofilter", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-bsfilter-plugin", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-clamd-plugin", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-dillo-viewer", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-extra-plugins", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-fancy-plugin", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-feeds-reader", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-fetchinfo-plugin", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-gdata-plugin", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-i18n", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-libravatar", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-litehtml-viewer", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-mailmbox-plugin", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-managesieve", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-multi-notifier", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-newmail-plugin", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-pdf-viewer", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-perl-filter", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-pgpinline", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-pgpmime", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-plugins", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-python-plugin", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-smime-plugin", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-spam-report", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-spamassassin", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-tnef-parser", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-tools", "binary_version": "4.0.0-3" }, { "binary_name": "claws-mail-vcalendar-plugin", "binary_version": "4.0.0-3" }, { "binary_name": "libclaws-mail-dev", "binary_version": "4.0.0-3" } ] }
{ "binaries": [ { "binary_name": "claws-mail", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-acpi-notifier", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-address-keeper", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-archiver-plugin", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-attach-remover", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-attach-warner", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-bogofilter", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-bsfilter-plugin", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-clamd-plugin", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-dillo-viewer", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-extra-plugins", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-fancy-plugin", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-feeds-reader", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-fetchinfo-plugin", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-i18n", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-keyword-warner", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-libravatar", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-litehtml-viewer", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-mailmbox-plugin", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-managesieve", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-multi-notifier", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-newmail-plugin", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-pdf-viewer", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-perl-filter", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-pgpinline", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-pgpmime", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-plugins", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-python-plugin", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-smime-plugin", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-spam-report", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-spamassassin", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-tnef-parser", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-tools", "binary_version": "4.2.0-2build7" }, { "binary_name": "claws-mail-vcalendar-plugin", "binary_version": "4.2.0-2build7" }, { "binary_name": "libclaws-mail-dev", "binary_version": "4.2.0-2build7" } ] }
{ "binaries": [ { "binary_name": "claws-mail", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-acpi-notifier", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-address-keeper", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-archiver-plugin", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-attach-remover", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-attach-warner", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-bogofilter", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-bsfilter-plugin", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-clamd-plugin", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-dillo-viewer", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-extra-plugins", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-fancy-plugin", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-feeds-reader", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-fetchinfo-plugin", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-i18n", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-keyword-warner", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-libravatar", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-litehtml-viewer", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-mailmbox-plugin", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-managesieve", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-multi-notifier", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-newmail-plugin", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-pdf-viewer", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-perl-filter", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-pgpinline", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-pgpmime", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-plugins", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-python-plugin", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-smime-plugin", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-spam-report", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-spamassassin", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-tnef-parser", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-tools", "binary_version": "4.3.1-1" }, { "binary_name": "claws-mail-vcalendar-plugin", "binary_version": "4.3.1-1" }, { "binary_name": "libclaws-mail-dev", "binary_version": "4.3.1-1" } ] }