Unrated severityNVD Advisory· Published May 16, 2018· Updated Aug 5, 2024
CVE-2017-17689
CVE-2017-17689
Description
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- osv-coords2 versionspkg:rpm/opensuse/enigmail&distro=openSUSE%20Tumbleweedpkg:rpm/suse/enigmail&distro=SUSE%20Package%20Hub%2012
< 2.2.4-1.4+ 1 more
- (no CPE)range: < 2.2.4-1.4
- (no CPE)range: < 2.0.4-9.1
Patches
Vulnerability mechanics
References
6- www.securityfocus.com/bid/104165mitrevdb-entryx_refsource_BID
- efail.demitrex_refsource_MISC
- news.ycombinator.com/itemmitrex_refsource_MISC
- pastebin.com/gNCc8aYmmitrex_refsource_MISC
- twitter.com/matthew_d_green/status/996371541591019520mitrex_refsource_MISC
- www.synology.com/support/security/Synology_SA_18_22mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.