PT-2021-4102 · Kde · Kde Messagelib

Ingo Klöcker

·

Published

2021-04-28

·

Updated

2024-06-15

·

CVE-2021-31855

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions KDE Messagelib versions prior to 5.17.0
Description The issue is related to the incorrect handling of attachment deletion in decrypted encrypted messages stored on remote servers, such as IMAP servers. When a user deletes an attachment from a decrypted encrypted message, the decrypted content of the message is uploaded to the remote server. This could allow an attacker, with access to the messages on the email server, to read the decrypted content of the encrypted message. The problem is specifically found in the ViewerPrivate::deleteAttachment function in messageviewer/src/viewer/viewer p.cpp.
Recommendations For KDE Messagelib versions prior to 5.17.0, as a temporary workaround, consider disabling the deleteAttachment function in ViewerPrivate until a patch is available. Restrict access to the messageviewer/src/viewer/viewer p.cpp component to minimize the risk of exploitation. Avoid deleting attachments from decrypted encrypted messages stored on remote servers until the issue is resolved.

Fix

Cleartext Storage of Sensitive Information

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04687
CVE-2021-31855
MGASA-2021-0208
OPENSUSE-SU-2024:11046-1

Affected Products

Kde Messagelib