openSUSE alert openSUSE-SU-2018:1451-1 (enigmail)
From: | opensuse-security@opensuse.org | |
To: | opensuse-updates@opensuse.org | |
Subject: | openSUSE-SU-2018:1451-1: moderate: Security update for enigmail | |
Date: | Mon, 28 May 2018 21:07:01 +0200 (CEST) | |
Message-ID: | <20180528190701.CDC84FD2B@maintenance.suse.de> |
openSUSE Security Update: Security update for enigmail ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:1451-1 Rating: moderate References: #1094781 Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for enigmail to version 2.0.6 fixes the following issues: Security issues fixed: - Replies to a partially encrypted message may have revealed protected information: no longer display PGP/MIME message part followed by unencrypted data (boo#1094781) - Signature could be spoofed via Inline-PGP in HTML Mails The following bugs were fixed: - Filter actions could forget selected mail folder names Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Package Hub for SUSE Linux Enterprise 12: zypper in -t patch openSUSE-2018-535=1 Package List: - SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 ppc64le s390x x86_64): enigmail-2.0.6-15.1 References: https://bugzilla.suse.com/1094781