5
CVSSv2

CVE-2017-9604

Published: 13/06/2017 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

KDE kmail prior to 5.5.2 and messagelib prior to 5.5.2, as distributed in KDE Applications prior to 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote malicious users to obtain sensitive information by sniffing the network.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kde messagelib

kde kmail

Vendor Advisories

Debian Bug report logs - #864803 CVE-2017-9604: Send Later with Delay bypasses OpenPGP Package: src:kf5-messagelib; Maintainer for src:kf5-messagelib is Debian/Kubuntu Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 15 Jun 2017 05:45:01 UTC Severit ...
It was found that KMail's Send Later with Delay function bypassed OpenPGP signing and encryption, causing the message to be sent unsigned and in plain-text A remote attacker, with access to the user's network traffic, could potentially use this flaw to obtain sensitive information from the plain-text email messages ...
KDE kmail before 552 and messagelib before 552, as distributed in KDE Applications before 17042, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network ...