CVE-2017-17689
16.05.2018, 19:29
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.Enginsight
| Vendor | Product | Version |
|---|---|---|
| 9folders | nine | - |
| apple | - | |
| bloop | airmail | - |
| emclient | emclient | - |
| flipdogsolutions | maildroid | - |
| freron | mailmate | - |
| gnome | evolution | - |
| gmail | - | |
| horde | horde_imp | - |
| ibm | notes | - |
| kde | kmail | - |
| kde | trojita | - |
| mozilla | thunderbird | - |
| postbox-inc | postbox | - |
| r2mail2 | r2mail2 | - |
| ritlabs | the_bat | - |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| evolution |
| ||||||||||||||||||||||||||||||||
| kmail |
| ||||||||||||||||||||||||||||||||
| thunderbird |
|
References