5.9

CVE-2017-17689

Exploit
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
9folders ≫ Nine Version -
Apple ≫ Mail Version -
Apple ≫ Mail Version - SwPlatform iphone_os
Bloop ≫ Airmail Version -
Emclient ≫ Emclient Version -
Flipdogsolutions ≫ Maildroid Version -
Freron ≫ Mailmate Version -
Gnome ≫ Evolution Version -
Google ≫ Gmail Version -
Horde ≫ Horde Imp Version -
Ibm ≫ Notes Version -
Kde ≫ Kmail Version -
Kde ≫ Trojita Version -
Microsoft ≫ Outlook Version 2007
Microsoft ≫ Outlook Version 2010
Microsoft ≫ Outlook Version 2013
Microsoft ≫ Outlook Version 2016
Mozilla ≫ Thunderbird Version -
Postbox-inc ≫ Postbox Version -
R2mail2 ≫ R2mail2 Version -
Ritlabs ≫ The Bat Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.17% 0.898
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://efail.de
Third Party Advisory
Exploit
Mitigation
https://news.ycombinator.com/item?id=17066419
Third Party Advisory
Issue Tracking
https://www.synology.com/support/security/Synology_SA_18_22
Third Party Advisory
http://www.securityfocus.com/bid/104165
Third Party Advisory
VDB Entry
https://pastebin.com/gNCc8aYm
Third Party Advisory
https://twitter.com/matthew_d_green/status/996371541591019520
Third Party Advisory