Regular Expression Denial of Service in Enigmail 1.9.9 and earlier

Regular Expression Denial of Service in Enigmail 1.9.9 and earlier

CVE-2017-17846 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:N/A:P

An issue was discovered in Enigmail before 1.9.9. Regular expressions are exploitable for Denial of Service, because of attempts to match arbitrarily long strings, aka TBE-01-003.

Learn more about our Web Application Penetration Testing UK.