CVE-2017-17689
Published May 16, 2018The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
- evidence mentions
- 2
- Buzz score
- 17.5
Vendor/product archive
2 CVEs tagged to postbox-inc / postbox — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report…