CVE-2017-17846: Debian Linux
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
An issue was discovered in Enigmail before 1.9.9. Regular expressions are exploitable for Denial of Service, because of attempts to match arbitrarily long strings, aka TBE-01-003.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Enigmail Enigmail: before 1.9.9 (fixed in 1.9.9)
Published 2017-12-27. Last modified 2026-06-17.