CVE-2017-9604: High severity kmail vulnerability
KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9604?
CVE-2017-9604 is considered a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2017-9604?
To fix CVE-2017-9604, upgrade KMail and MessageLib to version 5.5.2 or later.
What are the affected versions for CVE-2017-9604?
CVE-2017-9604 affects KDE KMail versions before 5.5.2 and KDE MessageLib before 5.5.2.
What does CVE-2017-9604 allow attackers to do?
CVE-2017-9604 allows remote attackers to obtain sensitive information by sniffing the network during the Send Later feature.
Are there any workarounds for CVE-2017-9604?
Currently, the recommended solution is to update to the patched versions as no effective workarounds are available for CVE-2017-9604.