The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2018-05-16 19:29
Updated : 2024-11-21 03:18
NVD link : CVE-2017-17688
Mitre link : CVE-2017-17688
CVE.ORG link : CVE-2017-17688
JSON object : View
Products Affected
roundcube
- webmail
mozilla
- thunderbird
freron
- mailmate
flipdogsolutions
- maildroid
horde
- horde_imp
postbox-inc
- postbox
r2mail2
- r2mail2
microsoft
- outlook
emclient
- emclient
apple
bloop
- airmail
CWE