|
|
| |
| When receiving of a clear signed S/MIME e-mail with a broken signature (for example, if the mail body is modified by a third party during transmission), Lotus Notes client will not warn the user about the broken signature. |
| |
Credit:
The information has been provided by Vinci Chou.
|
| |
Vulnerable systems:
All R5 client versions up to the latest R5.0.5
An e-mail that contains a bad S/MIME signature is displayed just like any unsigned e-mail. If you receive an encrypted S/MIME e-mail that is corrupted, Lotus Notes client will display a blank message. Other Internet mail clients would display warning messages in both cases, since a broken signature might be an indication of spoofing or tampering with the original.
Fixes:
No patch is available at this time.
|
|
|
|
|
|
|
|