CVE-2017-17688: Medium severity Apple Mail vulnerability
DISPUTED The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-17688?
CVE-2017-17688 is a vulnerability in the OpenPGP specification that allows a Cipher Feedback Mode (CFB) malleability-gadget attack leading to plaintext exfiltration.
What is the severity of CVE-2017-17688?
The severity of CVE-2017-17688 is medium, with a severity value of 5.9.
Which software is affected by CVE-2017-17688?
The following software is affected by CVE-2017-17688: Apple Mail, Bloop Airmail, Emclient Emclient, Flipdogsolutions Maildroid, Freron Mailmate, Horde Horde Imp, Microsoft Outlook (2007 version), Mozilla Thunderbird, Postbox-inc Postbox, R2mail2 R2mail2, Roundcube Webmail.
How does CVE-2017-17688 work?
CVE-2017-17688 allows a malleability-gadget attack that can indirectly lead to plaintext exfiltration by exploiting the Cipher Feedback Mode (CFB) in the OpenPGP specification.
Are there any references for CVE-2017-17688?
Yes, you can find references for CVE-2017-17688 at the following links: http://flaked.sockpuppet.org/2018/05/16/a-unified-timeline.html, http://www.securityfocus.com/bid/104162, http://www.securitytracker.com/id/1040904