Bug ID 1131801
Summary VUL-1: CVE-2019-10740: an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
URL https://smash.suse.de/issue/229067/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Security
Assignee security-team@suse.de
Reporter kbabioch@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

In Roundcube Webmail 1.3.4, an attacker in possession of S/MIME or PGP
encrypted
emails can wrap them as sub-parts within a crafted multipart email. The
encrypted part(s) can further be hidden using HTML/CSS or ASCII newline
characters. This modified multipart email can be re-sent by the attacker to the
intended receiver. If the receiver replies to this (benign looking) email, they
unknowingly leak the plaintext of the encrypted message part(s) back to the
attacker.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-10740
http://www.cvedetails.com/cve/CVE-2019-10740/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10740
https://github.com/roundcube/roundcubemail/issues/6638


You are receiving this mail because: