CVE-2014-8878: Medium severity kmail vulnerability
It was reported that sending OpenPGP/MIME encrypted emails with attachments does not encrypt the attachments.
Upstream report: https://bugs.kde.org/showbug.cgi?id=340312 Upstream fix: http://quickgit.kde.org/?p=kdepim.git&a=commit&h=626c857eb30c0533a4de7836ee843caaa8c00a26 CVE request: http://seclists.org/oss-sec/2015/q3/118
Other sources
KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain sensitive information by sniffing the network.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8878?
CVE-2014-8878 is considered to have a medium severity as it compromises the confidentiality of email attachments.
How do I fix CVE-2014-8878?
To fix CVE-2014-8878, upgrade to kdepim version 4.14.12 or later.
Which software is affected by CVE-2014-8878?
CVE-2014-8878 affects kdepim versions prior to 4.14.12 and KMail version 4.11.5.
What type of vulnerability is CVE-2014-8878?
CVE-2014-8878 is a vulnerability related to the improper encryption of attachments in OpenPGP/MIME encrypted emails.
Can CVE-2014-8878 be exploited remotely?
Yes, CVE-2014-8878 can be exploited remotely as it affects the handling of emails sent to users.