First published: Thu Jul 16 2015(Updated: )
It was reported that sending OpenPGP/MIME encrypted emails with attachments does not encrypt the attachments. Upstream report: <a href="https://bugs.kde.org/show_bug.cgi?id=340312">https://bugs.kde.org/show_bug.cgi?id=340312</a> Upstream fix: <a href="http://quickgit.kde.org/?p=kdepim.git&a=commit&h=626c857eb30c0533a4de7836ee843caaa8c00a26">http://quickgit.kde.org/?p=kdepim.git&a=commit&h=626c857eb30c0533a4de7836ee843caaa8c00a26</a> CVE request: <a href="http://seclists.org/oss-sec/2015/q3/118">http://seclists.org/oss-sec/2015/q3/118</a>
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kdepim | <4.14.12 | 4.14.12 |
KMail | =4.11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8878 is considered to have a medium severity as it compromises the confidentiality of email attachments.
To fix CVE-2014-8878, upgrade to kdepim version 4.14.12 or later.
CVE-2014-8878 affects kdepim versions prior to 4.14.12 and KMail version 4.11.5.
CVE-2014-8878 is a vulnerability related to the improper encryption of attachments in OpenPGP/MIME encrypted emails.
Yes, CVE-2014-8878 can be exploited remotely as it affects the handling of emails sent to users.