cbcvebase.
CVE-2017-17688
published 2018-05-16

CVE-2017-17688: The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE…

PriorityP433medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
5.57%
92.0th percentile
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification

Affected

6 ranges
VendorProductVersion rangeFixed in
debianenigmail< enigmail 2:2.0.6.1-4 (bullseye)enigmail 2:2.0.6.1-4 (bullseye)
debianroundcube< roundcube 1.3.8+dfsg.1-1 (bookworm)roundcube 1.3.8+dfsg.1-1 (bookworm)
enigmailenigmail>= 0 < 2:2.0.6.1-42:2.0.6.1-4
enigmailenigmail>= 0 < 2:2.0.8-1~ubuntu0.16.04.22:2.0.8-1~ubuntu0.16.04.2
microsoftoutlook
roundcubewebmail< 1.3.71.3.7

CVSS provenance

nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.