PT-2017-19064 · Kde · Messagelib+2
Published
2017-06-13
·
Updated
2019-10-03
·
CVE-2017-9604
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
KDE kmail versions prior to 5.5.2
messagelib versions prior to 5.5.2
KDE Applications versions prior to 17.04.2
Description
The issue allows remote attackers to obtain sensitive information by sniffing the network, due to the lack of ensuring a plugin's sign/encrypt action during the use of the Send Later feature.
Recommendations
For KDE kmail versions prior to 5.5.2, update to version 5.5.2 or later to resolve the issue.
For messagelib versions prior to 5.5.2, update to version 5.5.2 or later to resolve the issue.
For KDE Applications versions prior to 17.04.2, update to version 17.04.2 or later to resolve the issue.
Fix
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kde Applications
Kde Kmail
Messagelib