SB2014082909 - Fedora 21 update for thunderbird-enigmail
Published: August 29, 2014 Updated: April 24, 2025
Security Bulletin ID
SB2014082909
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cryptographic issues (CVE-ID: CVE-2014-5369)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption is enabled and only BCC recipients are specified, which allows remote attackers to obtain sensitive information by sniffing the network.
Remediation
Install update from vendor's website.