First published: Tue Jun 13 2017(Updated: )
KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KDE KMail | <=5.5.1 | |
KDE Messagelib | <=5.5.1 | |
KDE KDE | =17.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9604 is considered a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2017-9604, upgrade KMail and MessageLib to version 5.5.2 or later.
CVE-2017-9604 affects KDE KMail versions before 5.5.2 and KDE MessageLib before 5.5.2.
CVE-2017-9604 allows remote attackers to obtain sensitive information by sniffing the network during the Send Later feature.
Currently, the recommended solution is to update to the patched versions as no effective workarounds are available for CVE-2017-9604.