Medium severity5.9NVD Advisory· Published May 16, 2018· Updated Jun 17, 2026
CVE-2017-17688
CVE-2017-17688
Description
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:a:apple:mail:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apple:mail:-:*:*:*:*:*:*:*
- cpe:2.3:a:apple:mail:-:*:*:*:*:iphone_os:*:*
- cpe:2.3:a:flipdogsolutions:maildroid:-:*:*:*:*:*:*:*
- cpe:2.3:a:horde:horde_imp:-:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:thunderbird:-:*:*:*:*:*:*:*
- cpe:2.3:a:postbox-inc:postbox:-:*:*:*:*:*:*:*
- osv-coords2 versionspkg:rpm/opensuse/enigmail&distro=openSUSE%20Tumbleweedpkg:rpm/suse/enigmail&distro=SUSE%20Package%20Hub%2012
< 2.2.4-1.4+ 1 more
- (no CPE)range: < 2.2.4-1.4
- (no CPE)range: < 2.0.4-9.1
Patches
Vulnerability mechanics
References
10- efail.denvdExploitMitigationThird Party Advisory
- flaked.sockpuppet.org/2018/05/16/a-unified-timeline.htmlnvdThird Party Advisory
- www.securityfocus.com/bid/104162nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1040904nvdThird Party AdvisoryVDB Entry
- lists.gnupg.org/pipermail/gnupg-users/2018-May/060334.htmlnvdThird Party Advisory
- news.ycombinator.com/itemnvdIssue TrackingThird Party Advisory
- protonmail.com/blog/pgp-vulnerability-efailnvdIssue TrackingThird Party Advisory
- twitter.com/matthew_d_green/status/995996706457243648nvdThird Party Advisory
- www.patreon.com/posts/cybersecurity-15-18814817nvdIssue TrackingThird Party Advisory
- www.synology.com/support/security/Synology_SA_18_22nvdThird Party Advisory
News mentions
0No linked articles in our index yet.