← Back

CVE-2017-17689

nvd nist
Published: May 16, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.9
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

Affected (21)

Products: 9folders: Nine · Apple: Mail · Bloop: Airmail · +13 more
Show all products
1 product
Nine
1 product
Mail
1 product
Airmail
1 product
Emclient
Maildroid
1 product
Mailmate
1 product
Evolution
1 product
Gmail
1 product
Horde Imp
1 product
Notes
2 products
Kmail
Trojita
1 product
Outlook
1 product
Thunderbird
1 product
Postbox
1 product
R2mail2
1 product
The Bat
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Apple
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
Microsoft
Version 2007
Version 2010
Version 2013
Version 2016
All versions
All versions
All versions
All versions

References (12)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitMitigationThird Party Advisory
Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.