Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2012-6580
HistoryJul 24, 2013 - 12:01 p.m.

CVE-2012-6580

2013-07-2412:01:45
Debian Security Bug Tracker
security-tracker.debian.org
10
best practical solutions
rt 3.8.x
rt 4.0.x
gnupg
unencrypted message
spoofing
remote attackers
email
encryption-policy audit
unix

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

49.2%

Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, does not ensure that the UI labels unencrypted messages as unencrypted, which might make it easier for remote attackers to spoof details of a message’s origin or interfere with encryption-policy auditing via an e-mail message to a queue’s address.

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

49.2%

Related for DEBIANCVE:CVE-2012-6580