7.8
CVSSv2

CVE-2006-5877

Published: 23/02/2007 Updated: 15/11/2008
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The enigmail extension prior to 0.94.2 does not properly handle large, encrypted file e-mail attachments, which allows remote malicious users to cause a denial of service (crash), as demonstrated with Mozilla Thunderbird.

Vulnerable Product Search on Vulmon Subscribe to Product

enigmail enigmail

Vendor Advisories

Debian Bug report logs - #406604 CVE-2006-5877: Enigmail crashes on inline gpg Packages: mozilla-thunderbird-enigmail, enigmail; Maintainer for mozilla-thunderbird-enigmail is (unknown); Maintainer for enigmail is Debian Mozilla Extension Maintainers <pkg-mozext-maintainers@listsaliothdebianorg>; Source for enigmail is src:enigma ...
Mikhail Markin reported that enigmail incorrectly handled memory allocations for certain large encrypted attachments This caused Thunderbird to crash and thus caused the entire message to be inaccessible ...