The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-kf5-messagelib | Jul 30, 2024 | May 16, 2018 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-mail-thunderbird-52-8-0-0-175-3-33-0-4-0oracle-solaris-11-3-upgrade-mail-thunderbird-plugin-thunderbird-lightning-52-8-0-0-175-3-33-0-4-0 | Aug 24, 2018 | May 16, 2018 | |
| Suse | — | suse-upgrade-enigmail | May 18, 2018 | May 16, 2018 |
| Ubuntu | ubuntu-pro-upgrade-accountwizardubuntu-pro-upgrade-kmailubuntu-pro-upgrade-libkf5messageviewer5ubuntu-pro-upgrade-libkf5messageviewer5abi4ubuntu-pro-upgrade-libkf5mimetreeparser5abi2ubuntu-pro-upgrade-libkf5templateparser5ubuntu-pro-upgrade-libkf5templateparser5abi2ubuntu-pro-upgrade-libmessageviewer4ubuntu-pro-upgrade-libtemplateparser4 | Nov 19, 2024 | May 16, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub