Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption is enabled and only BCC recipients are specified, which allows remote attackers to obtain sensitive information by sniffing the network.
| Software | From | Fixed in |
|---|---|---|
| enigmail / enigmail | 1.7.2 | 1.7.2.x |
| enigmail / enigmail | 1.7 | 1.7.x |