CVE-2019-8338

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/05/2019
Last modified:
21/05/2019

Description

The signature verification routine in the Airmail GPG-PGP Plugin, versions 1.0 (9) and earlier, does not verify the status of the signature at all, which allows remote attackers to spoof arbitrary email signatures by crafting a signed email with an invalid signature. Also, it does not verify the validity of the signing key, which allows remote attackers to spoof arbitrary email signatures by crafting a key with a fake user ID (email address) and injecting it into the user's keyring.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gpg-pgp_project:gpg-pgp:*:*:*:*:*:airmail:*:* 1.0\(9\) (including)