CVE-2017-17847: Debian Linux

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI does not properly distinguish between an attachment signature, and a signature that applies to the entire containing message, aka TBE-01-021. This is demonstrated by an e-mail message with an attachment that is a signed e-mail message in message/rfc822 format.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Enigmail Enigmail: before 1.9.9 (fixed in 1.9.9)

Published 2017-12-27. Last modified 2026-06-17.