Summary
The remote host is missing an update to enigmail
announced via advisory DSA 889-1.
A bug has been discovered in enigmail, GPG support for Mozilla MailNews and Mozilla Thunderbird, that can lead to the encryption of mail with the wrong public key, hence, potential disclosure of confidential data to others.
The old stable distribution (woody) does not contain enigmail packages.
Solution
For the stable distribution (sarge) this problem has been fixed in version 0.91-4sarge2.
For the unstable distribution (sid) this problem has been fixed in version 0.93-1.
We recommend that you upgrade your enigmail packages.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20889-1
Severity
Classification
-
CVE CVE-2005-3256 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities