{"id":"openSUSE-SU-2018:1329-1","summary":"Security update for enigmail","details":"This update for enigmail to version 2.0.4 fixes multiple issues.\n\nSecurity issues fixed:\n\n- CVE-2017-17688: CFB gadget attacks allowed to exfiltrate plaintext out of encrypted emails.\n  enigmail now fails on GnuPG integrity check warnings for old Algorithms (bsc#1093151)\n- CVE-2017-17689: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails (bsc#1093152)\n\nThis update also includes new and updated functionality:\n\n- The Encryption and Signing buttons now work for both OpenPGP and S/MIME.\n  Enigmail will chose between S/MIME or OpenPGP depending on whether the keys\n  for all recipients are available for the respective standard\n- Support for the Autocrypt standard, which is now enabled by default\n- Support for Pretty Easy Privacy (p≡p)\n- Support for Web Key Directory (WKD)\n- The message subject can now be encrypted and replaced with a dummy subject,\n  following the Memory Hole standard forprotected Email Headers\n- keys on keyring are automatically refreshed from keyservers at irregular intervals\n- Subsequent updates of Enigmail no longer require a restart of Thunderbird \n- Keys are internally addressed using the fingerprint instead of the key ID","modified":"2026-03-11T07:32:00.838468Z","published":"2018-05-17T11:35:48Z","related":["CVE-2017-17688","CVE-2017-17689"],"upstream":["CVE-2017-17688","CVE-2017-17689"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RNZBPQATLVKCT7P5YVUXDDVDFKRPUWP6/#RNZBPQATLVKCT7P5YVUXDDVDFKRPUWP6"},{"type":"REPORT","url":"https://bugzilla.suse.com/1093151"},{"type":"REPORT","url":"https://bugzilla.suse.com/1093152"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-17688"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-17689"}],"affected":[{"package":{"name":"enigmail","ecosystem":"SUSE:Package Hub 12","purl":"pkg:rpm/suse/enigmail&distro=SUSE%20Package%20Hub%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.4-9.1"}]}],"ecosystem_specific":{"binaries":[{"enigmail":"2.0.4-9.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2018:1329-1.json"}}],"schema_version":"1.7.5"}