CVE-2017-17688
openSUSE Security Advisory - openSUSE-SU-2018:1393-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification
** EN DISPUTA ** La especificación OpenPGP permite un ataque malleability-gadget Cipher Feedback Mode (CFB) que puede conducir indirectamente a la exfiltración en texto plano. Esto también se conoce como EFAIL. NOTA: terceros indican que este es un problema en aplicaciones que gestionan de manera incorrecta la característica de Modification Detection Code (MDC) o que afectan un tipo de paquete obsoleto, en lugar de un problema en la especificación OpenPGP.
An update that fixes two vulnerabilities is now available. This update for enigmail to version 2.0.4 fixes multiple issues. CFB gadget attacks allowed to exfiltrate plaintext out of encrypted emails. Enigmail now fails on GnuPG integrity check warnings for old Algorithms CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails This update also includes new and updated functionality. Enigmail will chose between S/MIME or OpenPGP depending on whether the keys for all recipients are available for the respective standard subject, following the Memory Hole standard for protected Email Headers intervals.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-15 CVE Reserved
- 2018-05-16 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2025-05-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://flaked.sockpuppet.org/2018/05/16/a-unified-timeline.html | Third Party Advisory | |
http://www.securityfocus.com/bid/104162 | Third Party Advisory | |
http://www.securitytracker.com/id/1040904 | Third Party Advisory | |
https://lists.gnupg.org/pipermail/gnupg-users/2018-May/060334.html | Third Party Advisory | |
https://news.ycombinator.com/item?id=17066419 | Issue Tracking | |
https://protonmail.com/blog/pgp-vulnerability-efail | Issue Tracking | |
https://twitter.com/matthew_d_green/status/995996706457243648 | Third Party Advisory | |
https://www.patreon.com/posts/cybersecurity-15-18814817 | Issue Tracking | |
https://www.synology.com/support/security/Synology_SA_18_22 | Third Party Advisory |
|
URL | Date | SRC |
---|---|---|
https://efail.de | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Mail Search vendor "Apple" for product "Mail" | - | - |
Affected
| ||||||
Apple Search vendor "Apple" | Mail Search vendor "Apple" for product "Mail" | - | iphone_os |
Affected
| ||||||
Bloop Search vendor "Bloop" | Airmail Search vendor "Bloop" for product "Airmail" | - | - |
Affected
| ||||||
Emclient Search vendor "Emclient" | Emclient Search vendor "Emclient" for product "Emclient" | - | - |
Affected
| ||||||
Flipdogsolutions Search vendor "Flipdogsolutions" | Maildroid Search vendor "Flipdogsolutions" for product "Maildroid" | - | - |
Affected
| ||||||
Freron Search vendor "Freron" | Mailmate Search vendor "Freron" for product "Mailmate" | - | - |
Affected
| ||||||
Horde Search vendor "Horde" | Horde Imp Search vendor "Horde" for product "Horde Imp" | - | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Outlook Search vendor "Microsoft" for product "Outlook" | 2007 Search vendor "Microsoft" for product "Outlook" and version "2007" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | - | - |
Affected
| ||||||
Postbox-inc Search vendor "Postbox-inc" | Postbox Search vendor "Postbox-inc" for product "Postbox" | - | - |
Affected
| ||||||
R2mail2 Search vendor "R2mail2" | R2mail2 Search vendor "R2mail2" for product "R2mail2" | - | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | - | - |
Affected
|