UbuntuUpdates.org

Package "enigmail"

Name: enigmail

Description:

GPG support for Thunderbird and Debian Icedove

Latest version: 2:2.1.6+ds1-1~ubuntu0.16.04.1
Release: xenial (16.04)
Level: security
Repository: universe
Homepage: https://www.enigmail.net/

Links


Download "enigmail"


Other versions of "enigmail" in Xenial

Repository Area Version
base universe 2:1.9.1-1
updates universe 2:2.1.6+ds1-1~ubuntu0.16.04.1

Changelog

Version: 2:1.9.9-0ubuntu0.16.04.1 2018-01-22 20:06:20 UTC

  enigmail (2:1.9.9-0ubuntu0.16.04.1) xenial-security; urgency=medium

  * SECURITY UPDATE: Update to 1.9.9 to fix multiple security issues
    - CVE-2017-17843, CVE-2017-17844, CVE-2017-17845, CVE-2017-17846,
      CVE-2017-17847, CVE-2017-17848

 -- Marc Deslauriers <email address hidden> Fri, 19 Jan 2018 10:36:27 -0500

Source diff to previous version
CVE-2017-17843 An issue was discovered in Enigmail before 1.9.9 that allows remote attackers to trigger use of an intended public key for encryption, because incorr
CVE-2017-17844 An issue was discovered in Enigmail before 1.9.9. A remote attacker can obtain cleartext content by sending an encrypted data block (that the attacke
CVE-2017-17845 An issue was discovered in Enigmail before 1.9.9. Improper Random Secret Generation occurs because Math.Random() is used by pretty Easy privacy (pEp)
CVE-2017-17846 An issue was discovered in Enigmail before 1.9.9. Regular expressions are exploitable for Denial of Service, because of attempts to match arbitrarily
CVE-2017-17847 An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI does not properly distinguish between an attachment s
CVE-2017-17848 An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages becau

Version: 2:1.9.7-1~ubuntu0.16.04.1 2017-05-16 21:06:55 UTC

  enigmail (2:1.9.7-1~ubuntu0.16.04.1) xenial-security; urgency=medium

  * Backport to yakkety
  * Revert "bump to debhelper 10"




About   -   Send Feedback to @ubuntu_updates