Bug ID 1115719
Summary VUL-1: CVE-2018-19205: roundcubemail: mishandled GnuPG MDC integrity-protection warnings
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
URL https://smash.suse.de/issue/219070/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Security
Assignee nix@opensuse.org
Reporter kbabioch@suse.com
QA Contact security-team@suse.de
CC aj@ajaissle.de, wolfgang@rosenauer.org
Found By Security Response Team
Blocker ---

CVE-2018-19205

Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings,
which
makes it easier for attackers to obtain sensitive information, a related issue
to CVE-2017-17688. This is associated with
plugins/enigma/lib/enigma_driver_gnupg.php.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-19205
https://roundcube.net/news/2018/07/27/update-1.3.7-released
https://github.com/roundcube/roundcubemail/releases/tag/1.3.7


You are receiving this mail because: