CVE-2017-17688
16.05.2018, 19:29
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specificationEnginsight
| Vendor | Product | Version |
|---|---|---|
| apple | - | |
| bloop | airmail | - |
| emclient | emclient | - |
| flipdogsolutions | maildroid | - |
| freron | mailmate | - |
| horde | horde_imp | - |
| mozilla | thunderbird | - |
| postbox-inc | postbox | - |
| r2mail2 | r2mail2 | - |
| roundcube | webmail | - |
𝑥
= Vulnerable software versions
Ubuntu Releases
References