PT-2017-19064 · Kde · Messagelib+2

Published

2017-06-13

·

Updated

2019-10-03

·

CVE-2017-9604

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions KDE kmail versions prior to 5.5.2 messagelib versions prior to 5.5.2 KDE Applications versions prior to 17.04.2
Description The issue allows remote attackers to obtain sensitive information by sniffing the network, due to the lack of ensuring a plugin's sign/encrypt action during the use of the Send Later feature.
Recommendations For KDE kmail versions prior to 5.5.2, update to version 5.5.2 or later to resolve the issue. For messagelib versions prior to 5.5.2, update to version 5.5.2 or later to resolve the issue. For KDE Applications versions prior to 17.04.2, update to version 17.04.2 or later to resolve the issue.

Fix

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9604
OPENSUSE-SU-2017:1748-1
OPENSUSE-SU-2017:1756-1

Affected Products

Kde Applications
Kde Kmail
Messagelib