CVE-2017-17689

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/05/2018
Last modified:
03/10/2019

Description

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:9folders:nine:-:*:*:*:*:*:*:*
cpe:2.3:a:apple:mail:-:*:*:*:*:*:*:*
cpe:2.3:a:apple:mail:-:*:*:*:*:iphone_os:*:*
cpe:2.3:a:bloop:airmail:-:*:*:*:*:*:*:*
cpe:2.3:a:emclient:emclient:-:*:*:*:*:*:*:*
cpe:2.3:a:flipdogsolutions:maildroid:-:*:*:*:*:*:*:*
cpe:2.3:a:freron:mailmate:-:*:*:*:*:*:*:*
cpe:2.3:a:gnome:evolution:-:*:*:*:*:*:*:*
cpe:2.3:a:google:gmail:-:*:*:*:*:*:*:*
cpe:2.3:a:horde:horde_imp:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:notes:-:*:*:*:*:*:*:*
cpe:2.3:a:kde:kmail:-:*:*:*:*:*:*:*
cpe:2.3:a:kde:trojita:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:outlook:2007:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:outlook:2010:*:*:*:*:*:*:*