<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for enigmail</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2018:2243-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2018-08-07T16:05:05Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2018-08-07T16:05:05Z</InitialReleaseDate>
    <CurrentReleaseDate>2018-08-07T16:05:05Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for enigmail</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for enigmail to 2.0.7 fixes the following issues:

These security issues were fixed:

- CVE-2018-12020: Mitigation against GnuPG signature spoofing:
  Email signatures could be spoofed via an embedded '--filename'
  parameter in OpenPGP literal data packets. This update prevents
  this issue from being exploited if GnuPG was not updated
  (boo#1096745)
- CVE-2018-12019: The signature verification routine interpreted
  User IDs as status/control messages and did not correctly keep
  track of the status of multiple signatures. This allowed remote
  attackers to spoof arbitrary email signatures via public keys
  containing crafted primary user ids (boo#1097525)
- Disallow plaintext (literal packets) outside of encrpyted packets
- Replies to a partially encrypted message may have revealed
  protected information - no longer display PGP/MIME message
  part followed by unencrypted data (bsc#1094781)
- Fix signature Spoofing via Inline-PGP in HTML Mails

These non-security issues were fixed:

- Fix filter actions forgetting selected mail folder names
- Fix compatibility issue with Thunderbird 60b7
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-SLE-Product-WE-15-2018-1514</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20182243-1/</URL>
      <Description>Link for SUSE-SU-2018:2243-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2018-August/004384.html</URL>
      <Description>E-Mail link for SUSE-SU-2018:2243-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1094781</URL>
      <Description>SUSE Bug 1094781</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1096745</URL>
      <Description>SUSE Bug 1096745</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1097525</URL>
      <Description>SUSE Bug 1097525</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-12019/</URL>
      <Description>SUSE CVE CVE-2018-12019 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-12020/</URL>
      <Description>SUSE CVE CVE-2018-12020 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Workstation Extension 15">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Workstation Extension 15">
        <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15" CPE="cpe:/o:suse:sle-we:15">SUSE Linux Enterprise Workstation Extension 15</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="enigmail-2.0.7-3.7.2">
      <FullProductName ProductID="enigmail-2.0.7-3.7.2">enigmail-2.0.7-3.7.2</FullProductName>
    </Branch>
    <Relationship ProductReference="enigmail-2.0.7-3.7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15:enigmail-2.0.7-3.7.2">enigmail-2.0.7-3.7.2 as a component of SUSE Linux Enterprise Workstation Extension 15</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not correctly keep track of the status of multiple signatures, which allows remote attackers to spoof arbitrary email signatures via public keys containing crafted primary user ids.</Note>
    </Notes>
    <CVE>CVE-2018-12019</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Workstation Extension 15:enigmail-2.0.7-3.7.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20182243-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-12019.html</URL>
        <Description>CVE-2018-12019</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1097525</URL>
        <Description>SUSE Bug 1097525</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.</Note>
    </Notes>
    <CVE>CVE-2018-12020</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Workstation Extension 15:enigmail-2.0.7-3.7.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20182243-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-12020.html</URL>
        <Description>CVE-2018-12020</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1096745</URL>
        <Description>SUSE Bug 1096745</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1101134</URL>
        <Description>SUSE Bug 1101134</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
