Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that contains security fixes can now be installed.. openSUSE Security Update: Security update for enigmail ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0250-1 Rating: moderate References: #1159973 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for enigmail fixes the following issues: enigmail was updated to 2.1.5: * Security issue: unsigned MIME parts displayed as signed (bsc#1159973) * Ensure that upgrading GnuPG 2.0.x to 2.2.x upgrade converts keyring format * Make Enigmail Compatible with Protected-Headers spec, draft 2 enigmail 2.1.4: * Fixes for UI glitches * Option to "Attach public key to messages" was not restored properly enigmail 2.1.3: * fix a bug in the setup wizard that could lead the wizard to never complete scanning the inbox This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-250=1 Package List: - openSUSE Leap 15.1 (x86_64): enigmail-2.1.5-lp151.2.9.1 References: https://bugzilla.suse.com/1159973 -- . OpenSUSE Security Patch: Resolution for Enigmail with Announcement ID openSUSE-SU-2020:0450-1.. openSUSE, Enigmail, security update. . LinuxSecurity.com Team
An update that contains security fixes can now be installed. . SUSE Security Update: Security update for enigmail ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0413-1 Rating: moderate References: #1159973 Affected Products: SUSE Linux Enterprise Workstation Extension 15-SP1 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for enigmail fixes the following issues: enigmail was updated to 2.1.5: * Security issue: unsigned MIME parts displayed as signed (bsc#1159973) * Ensure that upgrading GnuPG 2.0.x to 2.2.x upgrade converts keyring format * Make Enigmail Compatible with Protected-Headers spec, draft 2 enigmail 2.1.4: * Fixes for UI glitches * Option to "Attach public key to messages" was not restored properly enigmail 2.1.3: * fix a bug in the setup wizard that could lead the wizard to never complete scanning the inbox Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 15-SP1: zypper in -t patch SUSE-SLE-Product-WE-15-SP1-2020-413=1 Package List: - SUSE Linux Enterprise Workstation Extension 15-SP1 (x86_64): enigmail-2.1.5-3.22.1 References: https://bugzilla.suse.com/1159973 _______________________________________________ sle-security-updates mailing list
update to enigmail 2.1.5 Includes a security fix for "Unsigned MIME parts displayed as signed". --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-b48e3c177e 2020-01-24 17:07:54.394766 --------------------------------------------------------------------------------Name : thunderbird-enigmail Product : Fedora 31 Version : 2.1.5 Release : 1.fc31 URL : https://enigmail.net/index.php/en/ Summary : Authentication and encryption extension for Mozilla Thunderbird Description : Enigmail is an extension to the mail client Mozilla Thunderbird which allows users to access the authentication and encryption features provided by GnuPG --------------------------------------------------------------------------------Update Information: update to enigmail 2.1.5 Includes a security fix for "Unsigned MIME parts displayed as signed" --------------------------------------------------------------------------------ChangeLog: * Mon Jan 13 2020 Felix Schwarz - 2.1.5-1 - update to 2.1.5 * Tue Nov 12 2019 Felix Schwarz - 2.1.3-4 - do not build package on armv7hl/s390x (thunderbird not available there) * Mon Nov 11 2019 Felix Schwarz - 2.1.3-3 - enable GPG-based source file verification - package license file * Sat Nov 9 2019 Kai Hambrecht - 2.1.3-2 - adjust SPEC file rhbz#1752435 * Fri Nov 8 2019 Kai Hambrecht - 2.1.3-1 - update version to support TB 68 --------------------------------------------------------------------------------References: [ 1 ] Bug #1790323 - enigmail: Unsigned MIME parts displayed as signed https://bugzilla.redhat.com/show_bug.cgi?id=1790323 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-b48e3c177e' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2019-14664, CVE-2019-12269 and compatibility with Thunderbird 68. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-941d57ed72 2019-11-21 02:02:03.859554 --------------------------------------------------------------------------------Name : thunderbird-enigmail Product : Fedora 29 Version : 2.1.3 Release : 4.fc29 URL : https://enigmail.net/index.php/en/ Summary : Authentication and encryption extension for Mozilla Thunderbird Description : Enigmail is an extension to the mail client Mozilla Thunderbird which allows users to access the authentication and encryption features provided by GnuPG --------------------------------------------------------------------------------Update Information: Security fix for CVE-2019-14664, CVE-2019-12269 and compatibility with Thunderbird 68 --------------------------------------------------------------------------------ChangeLog: * Tue Nov 12 2019 Felix Schwarz - 2.1.3-4 - do not build package on armv7hl/s390x (thunderbird not available there) * Mon Nov 11 2019 Felix Schwarz - 2.1.3-3 - enable GPG-based source file verification - package license file * Sat Nov 9 2019 Kai Hambrecht - 2.1.3-2 - adjust SPEC file rhbz#1752435 * Fri Nov 8 2019 Kai Hambrecht - 2.1.3-1 - update version to support TB 68 --------------------------------------------------------------------------------References: [ 1 ] Bug #1660478 - thunderbird-enigmail: HTTP authentication dialog may be triggered [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1660478 [ 2 ] Bug #1752435 - enigmail version 2.1 needs to be packaged to work with thunderbird 68 https://bugzilla.redhat.com/show_bug.cgi?id=1752435 [ 3 ] Bug #1749211 - CVE-2019-14664 thunderbird-enigmail: information leak in response to encrypted mail [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1749211 [ 4 ] Bug #1712723 - CVE-2019-12269thunderbird-enigmail: signature spoofing in inline PGP message [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1712723 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-941d57ed72' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that contains security fixes can now be installed. . SUSE Security Update: Security update for enigmail ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2982-1 Rating: moderate References: #1141025 #1151317 Affected Products: SUSE Linux Enterprise Workstation Extension 15-SP1 SUSE Linux Enterprise Workstation Extension 15 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for enigmail fixes the following issues: - SeaMonkey is no longer supported. Update description and no longer put in SeaMonkey addons path (bsc#1151317) enigmail was updated 2.1.2: * compatibility with Mozilla Thunderbird 68 * New simplified setup wizard * Full support for keys.openpgp.org * Default to ECC keys on GnuPG 2.1 or later * Autocrypt: implemented key-gossip and updates to known keys enimail was updated to 2.0.12: * set the default keyserver to keys.openpgp.org in order to mitigate the SKS Keyserver Network Attack (bsc#1141025) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 15-SP1: zypper in -t patch SUSE-SLE-Product-WE-15-SP1-2019-2982=1 - SUSE Linux Enterprise Workstation Extension 15: zypper in -t patch SUSE-SLE-Product-WE-15-2019-2982=1 Package List: - SUSE Linux Enterprise Workstation Extension 15-SP1 (x86_64): enigmail-2.1.2-3.19.1 - SUSE Linux Enterprise Workstation Extension 15 (x86_64): enigmail-2.1.2-3.19.1 References: https://bugzilla.suse.com/1141025 https://bugzilla.suse.com/1151317 _______________________________________________ sle-security-updates mailing list
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for enigmail ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1612-1 Rating: important References: #1135855 Cross-References: CVE-2019-12269 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.1 openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for enigmail fixes the following issues: enigmail was updated to 2.0.11: * CVE-2019-12269: Specially crafted inline PGP messages could spoof a "correctly signed" message (boo#1135855) enigmail was updated to 2.0.10: * various bug fixes for configuring and handling encrypted e-mail * UI fixes for dialogs, messages, and dark Thunderbird themes Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2019-1612=1 - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-1612=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1612=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): enigmail-2.0.11-31.1 - openSUSE Leap 15.1 (x86_64): enigmail-2.0.11-lp151.2.3.1 - openSUSE Leap 15.0 (x86_64): enigmail-2.0.11-lp150.31.1 References: https://www.suse.com/security/cve/CVE-2019-12269.html https://bugzilla.suse.com/1135855 -- . openSUSE has released a crucial security patch for Enigmail, tackling a significant vulnerability associated with inline PGP message forgery.. openSUSE Enigmail Update, Security Fixes, Important Updates, PGP Spoofing. . Severity: Important.LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for enigmail ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1576-1 Rating: important References: #1135855 Cross-References: CVE-2019-12269 Affected Products: SUSE Linux Enterprise Workstation Extension 15-SP1 SUSE Linux Enterprise Workstation Extension 15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for enigmail to version 2.0.11 fixes the following issues: Security issue fixed: - CVE-2019-12269: Fixed an issue where a specially crafted inline PGP messages could spoof a "correctly signed" message (bsc#1135855). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 15-SP1: zypper in -t patch SUSE-SLE-Product-WE-15-SP1-2019-1576=1 - SUSE Linux Enterprise Workstation Extension 15: zypper in -t patch SUSE-SLE-Product-WE-15-2019-1576=1 Package List: - SUSE Linux Enterprise Workstation Extension 15-SP1 (x86_64): enigmail-2.0.11-3.16.1 - SUSE Linux Enterprise Workstation Extension 15 (x86_64): enigmail-2.0.11-3.16.1 References: https://www.suse.com/security/cve/CVE-2019-12269.html https://bugzilla.suse.com/1135855 _______________________________________________ sle-security-updates mailing list
An update that contains security fixes can now be installed. . SUSE Security Update: Security update for enigmail ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:4215-1 Rating: moderate References: #1118935 Affected Products: SUSE Linux Enterprise Workstation Extension 15 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for enigmail to version 2.0.9 fixes the following issues: Security issue fixed: - When using Web Key Discovery, a HTTP authentication may be triggered. This may trick users into possibly sending e-mail credentials (bsc#1118935). Non-security issues fixed: - pEp - PGP/MIME signed-only messages are ignored - Autocrypt overrules manually created Per-Recipient Rules - "Re:" prefix on subject line disappears when editing encrypted, saved draft Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 15: zypper in -t patch SUSE-SLE-Product-WE-15-2018-3024=1 Package List: - SUSE Linux Enterprise Workstation Extension 15 (x86_64): enigmail-2.0.9-3.13.1 References: https://bugzilla.suse.com/1118935 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.