Tracker / CVE-2017-17688
CVE-2017-17688
Medium 5.9
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification
Affected products and versions
| apple | |
|---|---|
| bloop | airmail |
| emclient | emclient |
| flipdogsolutions | maildroid |
| freron | mailmate |
| horde | horde_imp |
| microsoft | outlook |
| mozilla | thunderbird |
| postbox-inc | postbox |
| r2mail2 | r2mail2 |
| roundcube | webmail |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.