IT

Tracker / CVE-2017-17689

CVE-2017-17689

Medium 5.9

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

Affected products and versions

9folders nine
apple mail
bloop airmail
emclient emclient
flipdogsolutions maildroid
freron mailmate
gnome evolution
google gmail
horde horde_imp
ibm notes
kde kmail
kde trojita
microsoft outlook
mozilla thunderbird
postbox-inc postbox
r2mail2 r2mail2
ritlabs the_bat

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References