Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-9604

Опубликовано: 13 июн. 2017
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.

It was found that KMail's Send Later with Delay function bypassed OpenPGP signing and encryption, causing the message to be sent unsigned and in plain-text. A remote attacker, with access to the user's network traffic, could potentially use this flaw to obtain sensitive information from the plain-text email messages.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kdepimWill not fix
Red Hat Enterprise Linux 6kdepim3Not affected
Red Hat Enterprise Linux 7kdepimWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=1461756kmail: Send Later with Delay bypasses OpenPGP

EPSS

Процентиль: 49%
0.00263
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS3: 7.5
nvd
больше 8 лет назад

KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS3: 7.5
debian
больше 8 лет назад

KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in ...

suse-cvrf
больше 8 лет назад

Security update for kdepim4

CVSS3: 7.5
github
больше 3 лет назад

KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.

EPSS

Процентиль: 49%
0.00263
Низкий

5.4 Medium

CVSS3