PT-2017-19064 · Kde · Messagelib+2
Publicado
2017-06-13
·
Atualizado
2019-10-03
·
CVE-2017-9604
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
KDE kmail versions prior to 5.5.2
messagelib versions prior to 5.5.2
KDE Applications versions prior to 17.04.2
Description
The issue allows remote attackers to obtain sensitive information by sniffing the network, due to the lack of ensuring a plugin's sign/encrypt action during the use of the Send Later feature.
Recommendations
For KDE kmail versions prior to 5.5.2, update to version 5.5.2 or later to resolve the issue.
For messagelib versions prior to 5.5.2, update to version 5.5.2 or later to resolve the issue.
For KDE Applications versions prior to 17.04.2, update to version 17.04.2 or later to resolve the issue.
Correção
Missing Encryption of Sensitive Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Kde Applications
Kde Kmail
Messagelib