It was discovered that an HTTP basic authentication dialog could be triggered when using enigmail and Web Key Discovery, an optional OpenPGP feature. Entering a recipient address will issue HTTP request which, in return, may cause an auth dialog to appear. The scenario is that e-mail or other credentials will be entered by the user. References: https://seclists.org/oss-sec/2018/q4/204 Upstream issue: https://sourceforge.net/p/enigmail/bugs/890/
Created thunderbird-enigmail tracking bugs for this issue: Affects: epel-7 [bug 1660479] Affects: fedora-all [bug 1660478]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.