Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

openSUSE 15.0: 2018:1347-1 Moderate: Enigmail Email Encryption Threat

opensuse
Calendar Grey May 19, 2018
Scroller Opensuse
Enhance your safety with Fedora's recent patch for gpg4win tackling vital security vulnerabilities.
An update that fixes two vulnerabilities is now available.

Description

This update for enigmail fixes multiple issues.

Security issues fixed:

- CVE-2017-17688: CFB gadget attacks allowed to exfiltrate plaintext out

of encrypted emails. enigmail now fails on GnuPG integrity check

warnings for old Algorithms (bsc#1093151)

- CVE-2017-17689: CBC gadget attacks allows to exfiltrate plaintext out of

encrypted emails (bsc#1093152)

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2018-474=1

Package List

- openSUSE Leap 15.0 (x86_64):

enigmail-2.0.4-lp150.2.3.1

References

https://www.suse.com/security/cve/CVE-2017-17688.html

https://www.suse.com/security/cve/CVE-2017-17689.html

https://bugzilla.suse.com/1093151

https://bugzilla.suse.com/1093152

--

Announcement ID: openSUSE-SU-2018:1347-1
Rating: moderate
Affected Products: openSUSE Leap 15.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.