Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-17689

Опубликовано: 16 мая 2018
Источник: debian
EPSS Низкий

Описание

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
evolutionunfixedpackage
kf5-messagelibfixed4:18.08.1-1package
kf5-messagelibno-dsastretchpackage
kdepimremovedpackage
kdepimno-dsastretchpackage
kdepimno-dsajessiepackage

Примечания

  • https://efail.de

  • https://bugzilla.gnome.org/show_bug.cgi?id=796135

  • https://dot.kde.org/2018/05/15/efail-and-kmail

  • protocol vulnerability can't be fixed in implementations but they can prevent exploitation by disabling loading of remote content

  • kmail bug is #898634, but src:kmail is not affected, the code in question is in kf5-messagelib

  • kf5-messagelib: https://phabricator.kde.org/D12391 (v18.04.1)

  • kf5-messagelib: https://phabricator.kde.org/D12393 (v18.04.1)

  • kmail: https://phabricator.kde.org/D12394

EPSS

Процентиль: 74%
0.00822
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 7 лет назад

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVSS3: 5.3
redhat
больше 7 лет назад

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVSS3: 5.9
nvd
больше 7 лет назад

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVSS3: 5.9
github
больше 3 лет назад

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

suse-cvrf
больше 7 лет назад

Security update for enigmail

EPSS

Процентиль: 74%
0.00822
Низкий