MidnightBSD

Advisories for postbox-inc

CVE-2017-17688 MEDIUM

The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
freron mailmate -
bloop airmail -
emclient emclient -
microsoft outlook 2007
mozilla thunderbird -
horde horde_imp -
roundcube webmail -
apple mail -
postbox-inc postbox -
r2mail2 r2mail2 -
flipdogsolutions maildroid -
CVE-2017-17689 MEDIUM

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
bloop airmail -
mozilla thunderbird -
horde horde_imp -
gnome evolution -
microsoft outlook 2016
ibm notes -
r2mail2 r2mail2 -
flipdogsolutions maildroid -
ritlabs the_bat -
freron mailmate -
microsoft outlook 2010
microsoft outlook 2013
emclient emclient -
microsoft outlook 2007
google gmail -
kde trojita -
kde kmail -
apple mail -
postbox-inc postbox -
9folders nine -