MidnightBSD

Advisories for flipdogsolutions

CVE-2017-17688 MEDIUM

The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
roundcube webmail -
apple mail -
bloop airmail -
freron mailmate -
horde horde_imp -
postbox-inc postbox -
emclient emclient -
flipdogsolutions maildroid -
microsoft outlook 2007
r2mail2 r2mail2 -
mozilla thunderbird -
CVE-2017-17689 MEDIUM

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
postbox-inc postbox -
emclient emclient -
microsoft outlook 2016
r2mail2 r2mail2 -
google gmail -
microsoft outlook 2013
ibm notes -
ritlabs the_bat -
apple mail -
9folders nine -
kde trojita -
bloop airmail -
freron mailmate -
microsoft outlook 2010
horde horde_imp -
kde kmail -
gnome evolution -
flipdogsolutions maildroid -
microsoft outlook 2007
mozilla thunderbird -