Medium severity5.9NVD Advisory· Published May 16, 2018· Updated Jun 17, 2026
CVE-2017-17689
CVE-2017-17689
Description
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
23cpe:2.3:a:apple:mail:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apple:mail:-:*:*:*:*:*:*:*
- cpe:2.3:a:apple:mail:-:*:*:*:*:iphone_os:*:*
- cpe:2.3:a:flipdogsolutions:maildroid:-:*:*:*:*:*:*:*
- cpe:2.3:a:gnome:evolution:-:*:*:*:*:*:*:*
- cpe:2.3:a:horde:horde_imp:-:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:thunderbird:-:*:*:*:*:*:*:*
- cpe:2.3:a:postbox-inc:postbox:-:*:*:*:*:*:*:*
- osv-coords2 versionspkg:rpm/opensuse/enigmail&distro=openSUSE%20Tumbleweedpkg:rpm/suse/enigmail&distro=SUSE%20Package%20Hub%2012
< 2.2.4-1.4+ 1 more
- (no CPE)range: < 2.2.4-1.4
- (no CPE)range: < 2.0.4-9.1
Patches
Vulnerability mechanics
References
6- efail.denvdExploitMitigationThird Party Advisory
- www.securityfocus.com/bid/104165nvdThird Party AdvisoryVDB Entry
- news.ycombinator.com/itemnvdIssue TrackingThird Party Advisory
- pastebin.com/gNCc8aYmnvdThird Party Advisory
- twitter.com/matthew_d_green/status/996371541591019520nvdThird Party Advisory
- www.synology.com/support/security/Synology_SA_18_22nvdThird Party Advisory
News mentions
0No linked articles in our index yet.