CVE-2019-10732
published 2019-04-07CVE-2019-10732: In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted…
PriorityP419medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.59%
44.8th percentile
In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | kf5-messagelib | < kf5-messagelib 4:19.08.3-1 (bookworm) | kf5-messagelib 4:19.08.3-1 (bookworm) |
| kde | kmail | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PIM Messagelib vulnerabilities
vendor_ubuntu·2025-09-02·CVSS 5.9
CVE-2017-17689 [MEDIUM] PIM Messagelib vulnerabilities
Title: PIM Messagelib vulnerabilities
Summary: Several security issues were fixed in PIM Messagelib.
Damian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising,
Sebastian Schinzel, Simon Friedberger, Juraj Somorovsky, and Jörg
Schwenk discovered that PIM Messagelib could be made to leak the plaintext
of S/MIME encrypted emails when retrieving external content in emails.
Under certain configurations, if a user were tricked into opening a
specially crafted email using an application linked against PIM Messagelib,
an attacker could possibly use this issue to obtain the plaintext of an
encrypted email. This update mitigates the issue by preventing automatic
loading of external content. (CVE-2017-17689)
Jens Müller, Marcus Brinkmann, Damian Poddebniak, Sebastian Schinzel,
and Jörg Schwen
Ubuntu
KDE PIM vulnerabilities
vendor_ubuntu·2025-09-02·CVSS 5.9
CVE-2024-50624 [MEDIUM] KDE PIM vulnerabilities
Title: KDE PIM vulnerabilities
Summary: Several security issues were fixed in KDE PIM.
Damian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising,
Sebastian Schinzel, Simon Friedberger, Juraj Somorovsky, and Jörg
Schwenk discovered that the KMail application of KDE PIM could be made
to leak the plaintext of S/MIME encrypted emails when retrieving
external content in emails. Under certain configurations, if a user were
tricked into opening a specially crafted email, an attacker could
possibly use this issue to obtain the plaintext of an encrypted email.
This update mitigates the issue by preventing KMail from automatically
loading external content. (CVE-2017-17689)
Jens Müller, Marcus Brinkmann, Damian Poddebniak, Sebastian Schinzel,
and Jörg Schwenk discovered that the KMail applica
Debian
CVE-2019-10732: kf5-messagelib - In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails ...
vendor_debian·2019·CVSS 4.3
CVE-2019-10732 [MEDIUM] CVE-2019-10732: kf5-messagelib - In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails ...
In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.
Scope: local
bookworm: resolved (fixed in 4:19.08.3-1)
bullseye: resolved (fixed in 4:19.08.3-1)
OSV
kf5-messagelib vulnerabilities
osv·2025-09-02·CVSS 5.9
[MEDIUM] kf5-messagelib vulnerabilities
kf5-messagelib vulnerabilities
Damian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising,
Sebastian Schinzel, Simon Friedberger, Juraj Somorovsky, and Jörg
Schwenk discovered that PIM Messagelib could be made to leak the plaintext
of S/MIME encrypted emails when retrieving external content in emails.
Under certain configurations, if a user were tricked into opening a
specially crafted email using an application linked against PIM Messagelib,
an attacker could possibly use this issue to obtain the plaintext of an
encrypted email. This update mitigates the issue by preventing automatic
loading of external content. (CVE-2017-17689)
Jens Müller, Marcus Brinkmann, Damian Poddebniak, Sebastian Schinzel,
and Jörg Schwenk discovered that PIM Messagelib could be made to leak the
plaintext of
OSV
kdepim vulnerabilities
osv·2025-09-02·CVSS 5.9
[MEDIUM] kdepim vulnerabilities
kdepim vulnerabilities
Damian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising,
Sebastian Schinzel, Simon Friedberger, Juraj Somorovsky, and Jörg
Schwenk discovered that the KMail application of KDE PIM could be made
to leak the plaintext of S/MIME encrypted emails when retrieving
external content in emails. Under certain configurations, if a user were
tricked into opening a specially crafted email, an attacker could
possibly use this issue to obtain the plaintext of an encrypted email.
This update mitigates the issue by preventing KMail from automatically
loading external content. (CVE-2017-17689)
Jens Müller, Marcus Brinkmann, Damian Poddebniak, Sebastian Schinzel,
and Jörg Schwenk discovered that the KMail application of KDE PIM could
be made to leak the plaintext of S/MIME or
GHSA
GHSA-87wx-cphx-3wgj: In KDE KMail 5
ghsa_unreviewed·2022-05-13
CVE-2019-10732 [MEDIUM] CWE-319 GHSA-87wx-cphx-3wgj: In KDE KMail 5
In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.
OSV
CVE-2019-10732: In KDE KMail 5
osv·2019-04-07·CVSS 4.3
CVE-2019-10732 [MEDIUM] CVE-2019-10732: In KDE KMail 5
In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10732 kmail: decryption based on replying to PGP or S/MIME encrypted emails
bugzilla·2019-04-10·CVSS 4.3
CVE-2019-10732 [MEDIUM] CVE-2019-10732 kmail: decryption based on replying to PGP or S/MIME encrypted emails
CVE-2019-10732 kmail: decryption based on replying to PGP or S/MIME encrypted emails
In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails
can wrap them as sub-parts within a crafted multipart email. The encrypted
part(s) can further be hidden using HTML/CSS or ASCII newline characters. This
modified multipart email can be re-sent by the attacker to the intended
receiver. If the receiver replies to this (benign looking) email, they
unknowingly leak the plaintext of the encrypted message part(s) back to the
attacker.
Reference:
https://bugs.kde.org/show_bug.cgi?id=404698
Discussion:
Created kmail tracking bugs for this issue:
Affects: fedora-all [bug 1698387]
Created kmail-account-wizard tracking bugs for this issue:
Affects: fedora-all [bug 1698388]
---
Bugzilla
CVE-2019-10732 kmail-account-wizard: kmail: decryption based on replying to PGP or S/MIME encrypted emails [fedora-all]
bugzilla·2019-04-10·CVSS 4.3
CVE-2019-10732 [MEDIUM] CVE-2019-10732 kmail-account-wizard: kmail: decryption based on replying to PGP or S/MIME encrypted emails [fedora-all]
CVE-2019-10732 kmail-account-wizard: kmail: decryption based on replying to PGP or S/MIME encrypted emails [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2019-10732 kmail: decryption based on replying to PGP or S/MIME encrypted emails [fedora-all]
bugzilla·2019-04-10·CVSS 4.3
CVE-2019-10732 [MEDIUM] CVE-2019-10732 kmail: decryption based on replying to PGP or S/MIME encrypted emails [fedora-all]
CVE-2019-10732 kmail: decryption based on replying to PGP or S/MIME encrypted emails [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
2019-04-07
Published