Lucene search

K
ubuntucveUbuntu.comUB:CVE-2019-14664
HistoryAug 05, 2019 - 12:00 a.m.

CVE-2019-14664

2019-08-0500:00:00
ubuntu.com
ubuntu.com
10

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.003

Percentile

72.1%

In Enigmail below 2.1, an attacker in possession of PGP encrypted emails
can wrap them as sub-parts within a crafted multipart email. The encrypted
part(s) can further be hidden using HTML/CSS or ASCII newline characters.
This modified multipart email can be re-sent by the attacker to the
intended receiver. If the receiver replies to this (benign looking) email,
he unknowingly leaks the plaintext of the encrypted message part(s) back to
the attacker. This attack variant bypasses protection mechanisms
implemented after the “EFAIL” attacks.

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.003

Percentile

72.1%