Improper Random Secret Generation in Enigmail: TBE-01-001

Improper Random Secret Generation in Enigmail: TBE-01-001

CVE-2017-17845 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

An issue was discovered in Enigmail before 1.9.9. Improper Random Secret Generation occurs because Math.Random() is used by pretty Easy privacy (pEp), aka TBE-01-001.

Learn more about our Web Application Penetration Testing UK.