K-9 Mail v5.600 can include the original quoted HTML code of a specially crafted, benign looking, email within (digitally signed) reply messages. The quoted part can contain conditional statements that show completely different text if opened in a different email client. This can be abused by an attacker to obtain valid S/MIME or PGP signatures for arbitrary content to be displayed to a third party. NOTE: the vendor states "We don't plan to take any action because of this."
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/k9mail/k-9/issues/3925 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-04-07T14:37:51
Updated: 2024-08-04T22:32:01.213Z
Reserved: 2019-04-03T00:00:00
Link: CVE-2019-10741
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-04-07T15:29:00.450
Modified: 2024-11-21T04:19:49.723
Link: CVE-2019-10741
Redhat
No data.