Unrated severityNVD Advisory· Published May 16, 2018· Updated Aug 5, 2024
CVE-2017-17688
CVE-2017-17688
Description
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/enigmail&distro=openSUSE%20Tumbleweedpkg:rpm/suse/enigmail&distro=SUSE%20Package%20Hub%2012
< 2.2.4-1.4+ 1 more
- (no CPE)range: < 2.2.4-1.4
- (no CPE)range: < 2.0.4-9.1
Patches
Vulnerability mechanics
References
10- flaked.sockpuppet.org/2018/05/16/a-unified-timeline.htmlmitrex_refsource_MISC
- www.securityfocus.com/bid/104162mitrevdb-entryx_refsource_BID
- www.securitytracker.com/id/1040904mitrevdb-entryx_refsource_SECTRACK
- efail.demitrex_refsource_MISC
- lists.gnupg.org/pipermail/gnupg-users/2018-May/060334.htmlmitrex_refsource_MISC
- news.ycombinator.com/itemmitrex_refsource_MISC
- protonmail.com/blog/pgp-vulnerability-efailmitrex_refsource_MISC
- twitter.com/matthew_d_green/status/995996706457243648mitrex_refsource_MISC
- www.patreon.com/posts/cybersecurity-15-18814817mitrex_refsource_MISC
- www.synology.com/support/security/Synology_SA_18_22mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.