MidnightBSD

Advisories for r2mail2

CVE-2017-17688 MEDIUM

The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
apple mail -
postbox-inc postbox -
horde horde_imp -
flipdogsolutions maildroid -
microsoft outlook 2007
mozilla thunderbird -
bloop airmail -
r2mail2 r2mail2 -
freron mailmate -
emclient emclient -
roundcube webmail -
CVE-2017-17689 MEDIUM

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
ritlabs the_bat -
horde horde_imp -
kde trojita -
flipdogsolutions maildroid -
microsoft outlook 2007
kde kmail -
bloop airmail -
r2mail2 r2mail2 -
freron mailmate -
microsoft outlook 2013
emclient emclient -
google gmail -
ibm notes -
apple mail -
postbox-inc postbox -
9folders nine -
microsoft outlook 2016
gnome evolution -
mozilla thunderbird -
microsoft outlook 2010