CVE-2017-17689
published 2018-05-16CVE-2017-17689: The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
PriorityP431medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
4.22%
89.9th percentile
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | evolution | < kf5-messagelib 4:18.08.1-1 (bookworm) | kf5-messagelib 4:18.08.1-1 (bookworm) |
| debian | kf5-messagelib | < kf5-messagelib 4:18.08.1-1 (bookworm) | kf5-messagelib 4:18.08.1-1 (bookworm) |
| kmail | kmail | >= 0 < 4:17.12.3-0ubuntu1+esm1 | 4:17.12.3-0ubuntu1+esm1 |
| kmail | kmail | >= 0 < 4:19.12.3-0ubuntu1+esm1 | 4:19.12.3-0ubuntu1+esm1 |
| microsoft | outlook | — | — |
| microsoft | outlook | — | — |
| microsoft | outlook | — | — |
| microsoft | outlook | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PIM Messagelib vulnerabilities
vendor_ubuntu·2025-09-02·CVSS 5.9
CVE-2017-17689 [MEDIUM] PIM Messagelib vulnerabilities
Title: PIM Messagelib vulnerabilities
Summary: Several security issues were fixed in PIM Messagelib.
Damian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising,
Sebastian Schinzel, Simon Friedberger, Juraj Somorovsky, and Jörg
Schwenk discovered that PIM Messagelib could be made to leak the plaintext
of S/MIME encrypted emails when retrieving external content in emails.
Under certain configurations, if a user were tricked into opening a
specially crafted email using an application linked against PIM Messagelib,
an attacker could possibly use this issue to obtain the plaintext of an
encrypted email. This update mitigates the issue by preventing automatic
loading of external content. (CVE-2017-17689)
Jens Müller, Marcus Brinkmann, Damian Poddebniak, Sebastian Schinzel,
and Jörg Schwen
Ubuntu
KDE PIM vulnerabilities
vendor_ubuntu·2025-09-02·CVSS 5.9
CVE-2024-50624 [MEDIUM] KDE PIM vulnerabilities
Title: KDE PIM vulnerabilities
Summary: Several security issues were fixed in KDE PIM.
Damian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising,
Sebastian Schinzel, Simon Friedberger, Juraj Somorovsky, and Jörg
Schwenk discovered that the KMail application of KDE PIM could be made
to leak the plaintext of S/MIME encrypted emails when retrieving
external content in emails. Under certain configurations, if a user were
tricked into opening a specially crafted email, an attacker could
possibly use this issue to obtain the plaintext of an encrypted email.
This update mitigates the issue by preventing KMail from automatically
loading external content. (CVE-2017-17689)
Jens Müller, Marcus Brinkmann, Damian Poddebniak, Sebastian Schinzel,
and Jörg Schwenk discovered that the KMail applica
Ubuntu
KMail vulnerabilities
vendor_ubuntu·2025-09-02·CVSS 5.9
CVE-2017-17689 [MEDIUM] KMail vulnerabilities
Title: KMail vulnerabilities
Summary: Several security issues were fixed in KMail.
Damian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising,
Sebastian Schinzel, Simon Friedberger, Juraj Somorovsky, and Jörg
Schwenk discovered that KMail could be made to leak the plaintext
of S/MIME encrypted emails when retrieving external content in emails.
Under certain configurations, if a user were tricked into opening a
specially crafted email, an attacker could possibly use this issue to
obtain the plaintext of an encrypted email. This update mitigates the
issue by preventing KMail from automatically loading external content.
This issue only affected Ubuntu 18.04 LTS. (CVE-2017-17689)
It was discovered that KMail could be made to attach files to an email
without the user's knowledge. If a us
Red Hat
S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
vendor_redhat·2018-05-14·CVSS 5.9
CVE-2017-17689 [MEDIUM] CWE-200 S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
Statement: The research paper talks about use of HTML as a back channel to create an oracle for modified encrypted emails. HTML emails which use external links like "" can cause security issues if they are honored by the MUAs. Due to flaws in MIME parsers many MUAs seem to concatenate decrypted HTML mine parts which makes it easy to plan such snippets in HTML emails. Please refer to https://lists.gnupg.org/pipermail/gnupg-users/2018-May/060315.html about how GnuPG can mitigate this flaw.
For Thunderbird, this vulnerability was known as CVE-2018-5162 and reso
Debian
CVE-2017-17689: evolution - The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadge...
vendor_debian·2017·CVSS 5.9
CVE-2017-17689 [MEDIUM] CVE-2017-17689: evolution - The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadge...
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
kf5-messagelib vulnerabilities
osv·2025-09-02·CVSS 5.9
[MEDIUM] kf5-messagelib vulnerabilities
kf5-messagelib vulnerabilities
Damian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising,
Sebastian Schinzel, Simon Friedberger, Juraj Somorovsky, and Jörg
Schwenk discovered that PIM Messagelib could be made to leak the plaintext
of S/MIME encrypted emails when retrieving external content in emails.
Under certain configurations, if a user were tricked into opening a
specially crafted email using an application linked against PIM Messagelib,
an attacker could possibly use this issue to obtain the plaintext of an
encrypted email. This update mitigates the issue by preventing automatic
loading of external content. (CVE-2017-17689)
Jens Müller, Marcus Brinkmann, Damian Poddebniak, Sebastian Schinzel,
and Jörg Schwenk discovered that PIM Messagelib could be made to leak the
plaintext of
OSV
kdepim vulnerabilities
osv·2025-09-02·CVSS 5.9
[MEDIUM] kdepim vulnerabilities
kdepim vulnerabilities
Damian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising,
Sebastian Schinzel, Simon Friedberger, Juraj Somorovsky, and Jörg
Schwenk discovered that the KMail application of KDE PIM could be made
to leak the plaintext of S/MIME encrypted emails when retrieving
external content in emails. Under certain configurations, if a user were
tricked into opening a specially crafted email, an attacker could
possibly use this issue to obtain the plaintext of an encrypted email.
This update mitigates the issue by preventing KMail from automatically
loading external content. (CVE-2017-17689)
Jens Müller, Marcus Brinkmann, Damian Poddebniak, Sebastian Schinzel,
and Jörg Schwenk discovered that the KMail application of KDE PIM could
be made to leak the plaintext of S/MIME or
OSV
kmail vulnerabilities
osv·2025-09-02·CVSS 5.9
[MEDIUM] kmail vulnerabilities
kmail vulnerabilities
Damian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising,
Sebastian Schinzel, Simon Friedberger, Juraj Somorovsky, and Jörg
Schwenk discovered that KMail could be made to leak the plaintext
of S/MIME encrypted emails when retrieving external content in emails.
Under certain configurations, if a user were tricked into opening a
specially crafted email, an attacker could possibly use this issue to
obtain the plaintext of an encrypted email. This update mitigates the
issue by preventing KMail from automatically loading external content.
This issue only affected Ubuntu 18.04 LTS. (CVE-2017-17689)
It was discovered that KMail could be made to attach files to an email
without the user's knowledge. If a user were tricked into sending an
email created by a specially c
GHSA
GHSA-xv45-9768-g2mm: The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL
ghsa_unreviewed·2022-05-13
CVE-2017-17689 [MEDIUM] GHSA-xv45-9768-g2mm: The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
OSV
CVE-2017-17689: The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL
osv·2018-05-16·CVSS 5.9
CVE-2017-17689 [MEDIUM] CVE-2017-17689: The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-17688 CVE-2017-17689 thunderbird: various flaws [fedora-all]
bugzilla·2018-05-14·CVSS 5.9
CVE-2017-17688 [MEDIUM] CVE-2017-17688 CVE-2017-17689 thunderbird: various flaws [fedora-all]
CVE-2017-17688 CVE-2017-17689 thunderbird: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedo
Bugzilla
CVE-2017-17689 S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
bugzilla·2018-05-14·CVSS 5.9
CVE-2017-17689 [MEDIUM] CVE-2017-17689 S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
CVE-2017-17689 S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails
Vulnerabilities in S/MIME specification can be abused by so-called CBC gadget attacks to exfiltrate the plaintext from encrypted email. Attacker having access to encrypted emails of a victim can modify them to inject an image tag into them and create a single encrypted body part that exfiltrates its own plaintext when the victim opens the attacker email.
External References:
https://efail.de/
Discussion:
Created evolution tracking bugs for this issue:
Affects: fedora-all [bug 1577910]
Created kmail tracking bugs for this issue:
Affects: fedora-all [bug 1577911]
Created thunderbird tracking bugs for this issue:
Affects: fedora-all [bug 1577914]
Created thunderbird-enigmail tracking
Bugzilla
CVE-2017-17688 CVE-2017-17689 trojita: various flaws [fedora-all]
bugzilla·2018-05-14·CVSS 5.9
CVE-2017-17688 [MEDIUM] CVE-2017-17688 CVE-2017-17689 trojita: various flaws [fedora-all]
CVE-2017-17688 CVE-2017-17689 trojita: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2017-17688 CVE-2017-17689 thunderbird-enigmail: various flaws [fedora-all]
bugzilla·2018-05-14·CVSS 5.9
CVE-2017-17688 [MEDIUM] CVE-2017-17688 CVE-2017-17689 thunderbird-enigmail: various flaws [fedora-all]
CVE-2017-17688 CVE-2017-17689 thunderbird-enigmail: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2017-17688 CVE-2017-17689 kmail: various flaws [fedora-all]
bugzilla·2018-05-14·CVSS 5.9
CVE-2017-17688 [MEDIUM] CVE-2017-17688 CVE-2017-17689 kmail: various flaws [fedora-all]
CVE-2017-17688 CVE-2017-17689 kmail: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Wh
Bugzilla
CVE-2017-17688 CVE-2017-17689 thunderbird-enigmail: various flaws [epel-7]
bugzilla·2018-05-14·CVSS 5.9
CVE-2017-17688 [MEDIUM] CVE-2017-17688 CVE-2017-17689 thunderbird-enigmail: various flaws [epel-7]
CVE-2017-17688 CVE-2017-17689 thunderbird-enigmail: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg
Bugzilla
CVE-2017-17688 CVE-2017-17689 trojita: various flaws [epel-7]
bugzilla·2018-05-14·CVSS 5.9
CVE-2017-17688 [MEDIUM] CVE-2017-17688 CVE-2017-17689 trojita: various flaws [epel-7]
CVE-2017-17688 CVE-2017-17689 trojita: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg update' reque
Bugzilla
CVE-2017-17688 CVE-2017-17689 evolution-data-server: various flaws [fedora-all]
bugzilla·2018-05-14·CVSS 5.9
CVE-2017-17688 [MEDIUM] CVE-2017-17688 CVE-2017-17689 evolution-data-server: various flaws [fedora-all]
CVE-2017-17688 CVE-2017-17689 evolution-data-server: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Tenable
Advisory: Efail...PGP Has an Email Problem?
blogs_tenable·2018-05-14
Advisory: Efail...PGP Has an Email Problem?
Blog / Research
Subscribe
# Advisory: Efail...PGP Has an Email Problem?
Steve Tilson
May 14, 2018
4 Min Read
Email continues to be one of the most popular ways to communicate in the world today. And given the rapidly evolving threat landscape, email encryption has never been more critical. Pretty Good Privacy (PGP) has long been a trusted platform for encrypted messaging and remains a popular method of sending secure, private email.
On May 14, a research team led by Sebastian Schinzel, researcher and professor of computer security at Münster University of Applied Sciences, disclosed critical vulnerabilities in implementations of several email clients and the OpenPGP and S/MIME standards that could be exploited to disclose sensitive information by exfiltrating plaintext of encrypted m
Tenable
Advisory: Efail...PGP Has an Email Problem?
blogs_tenable·2018-05-14
Advisory: Efail...PGP Has an Email Problem?
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
CTF
20180601-ais3preexam / README
ctf_writeups·2018
20180601-ais3preexam / README
# AIS3 Pre-exam 2018
**It's recommended to read our responsive [web version](https://balsn.tw/ctf_writeup/20180601-ais3preexam/) of this writeup.**
- [AIS3 Pre-exam 2018](#ais3-pre-exam-2018)
- [Rev](#rev)
- [Pwn](#pwn)
- [Misc](#misc)
- [Misc 1](#misc-1)
- [Misc 2](#misc-2)
- [Misc 3](#misc-3)
- [Misc 4](#misc-4)
- [Web](#web)
- [Web 1](#web-1)
- [Web 2](#web-2)
- [Web 3](#web-3)
- [Web 4](#web-4)
- [Crypto](#crypto)
- [Crypto 1](#crypto-1)
- [Crypto 2](#crypto-2)
- [Crypto 3 (unsolved, thanks to @how2hack)](#crypto-3-unsolved-thanks-to-how2hack)
- [Crypto 4](#crypto-4)
[AIS3 (Advanced Information Security Summer School)](https://ais3.org/) is a cyber security course in Taiwan. Therefore this writeup will be written in Chinese:)
By @bookgin, @sces60107
And thanks to @how2hack for
http://www.securityfocus.com/bid/104165https://efail.dehttps://news.ycombinator.com/item?id=17066419https://pastebin.com/gNCc8aYmhttps://twitter.com/matthew_d_green/status/996371541591019520https://www.synology.com/support/security/Synology_SA_18_22http://www.securityfocus.com/bid/104165https://efail.dehttps://news.ycombinator.com/item?id=17066419https://pastebin.com/gNCc8aYmhttps://twitter.com/matthew_d_green/status/996371541591019520https://www.synology.com/support/security/Synology_SA_18_22
2018-05-16
Published