Lucene search

K
redhatcveRedhat.comRH:CVE-2017-17688
HistoryApr 04, 2020 - 5:18 p.m.

CVE-2017-17688

2020-04-0417:18:47
redhat.com
access.redhat.com
9

0.008 Low

EPSS

Percentile

82.2%

DISPUTED The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification.

Mitigation

The easiest way to mitigate this vulnerability is not to use HTML emails. If you really need to use them ensure that MUA clients disable external links embedded in HTML emails. For example in thunderbird email client, Edit->Preferences->Privacy->Disable "Allow remote content in messages".