CVE-2017-9604

CWE-311CWE-20113 documents8 sources
Severity
7.5HIGH
EPSS
0.3%
top 50.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 13
Latest updateMay 13

Description

KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Debiankf5-messagelib< 4:16.04.3-3+1
NVDkde/kmail5.5.1
NVDkde/messagelib5.5.1

Patches

🔴Vulnerability Details

4
GHSA
GHSA-7w32-mxrp-49jg: KDE kmail before 52022-05-13
OSV
CVE-2017-9604: KDE kmail before 52017-06-13
CVEList
CVE-2017-9604: KDE kmail before 52017-06-13
Kernel
Merge tag 'keys-fixes-20170419' of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs2017-04-20

📋Vendor Advisories

2
Red Hat
kmail: Send Later with Delay bypasses OpenPGP2017-06-13
Debian
CVE-2017-9604: kf5-messagelib - KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applic...2017

💬Community

6
Bugzilla
CVE-2017-9604 kmail: Send Later with Delay bypasses OpenPGP2017-06-15
Bugzilla
CVE-2017-9604 kdepim3: kmail: Send Later with Delay bypasses OpenPGP [fedora-all]2017-06-15
Bugzilla
CVE-2017-9604 kdepim3: kmail: Send Later with Delay bypasses OpenPGP [epel-7]2017-06-15
Bugzilla
CVE-2017-9604 kf5-messagelib: kmail: Send Later with Delay bypasses OpenPGP [fedora-all]2017-06-15
Bugzilla
CVE-2017-9604 kdepim4: kmail: Send Later with Delay bypasses OpenPGP [fedora-all]2017-06-15
CVE-2017-9604 (HIGH CVSS 7.5) | KDE kmail before 5.5.2 and messagel | cvebase.io