Bugzilla – Bug 893330
VUL-0: CVE-2014-5369: enigmail: mail with only Bcc recipients sent in plain text
Last modified: 2014-09-08 14:04:24 UTC
Via oss-security: http://seclists.org/oss-sec/2014/q3/436 -------------- > http://sourceforge.net/p/enigmail/forum/support/thread/3e7268a4/ This seems to discuss at least two non-identical issues. http://sourceforge.net/p/enigmail/forum/support/thread/3e7268a4/#b315 and http://sourceforge.net/p/enigmail/bugs/294/ are about "an email with only Bcc recipients is sent in plain text." This is assigned CVE-2014-5369. http://sourceforge.net/p/enigmail/forum/support/thread/3e7268a4/#10f1 and http://sourceforge.net/p/enigmail/forum/support/thread/3e7268a4/#0a5a are about one or more issues in which there is unexpected cleartext e-mail transmission unrelated to use of Bcc. This perhaps requires a non-default configuration. It is conceivable -- although perhaps unlikely -- that the problem is a UI bug (e.g., an encryption choice is presented even when the product is configured to never use encryption). In any case, none of this has a CVE assignment yet. There isn't enough information to determine whether to assign zero, one, or two additional CVE IDs. The scope of CVE-2014-5369 is only the behavior that occurs when all recipients are Bcc recipients. Finally, these are additional (possibly related) references that haven't yet been mentioned on oss-security: http://sourceforge.net/p/enigmail/bugs/290/ http://twitter.com/mtigas/statuses/494228366028210176/photo/1 -------------- References: http://seclists.org/oss-sec/2014/q3/394 https://bugzilla.redhat.com/show_bug.cgi?id=1133373 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-5369 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5369
bugbot adjusting priority
Version 1.7.2 was released and I'm about to prepare it. Should I submit as soon as ready or should we add enigmail as part of next week's Mozilla updates (Firefox, Thunderbird)?
After the update includes a security-fix, I changed needinfo to the security-team. Thanks Wolfgang.
as it is a seperate package you can submit it seperately.
Update packages submitted
released
openSUSE-SU-2014:1096-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 893330 CVE References: CVE-2014-5369 Sources used: openSUSE 13.1 (src): enigmail-1.7.2-6.1 openSUSE 12.3 (src): enigmail-1.7.2-6.1