Back to search
CVE-2017-17688
Published: May 16, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://protonmail.com/blog/pgp-vulnerability-efail
x_refsource_MISC
https://news.ycombinator.com/item?id=17066419
x_refsource_MISC
https://www.patreon.com/posts/cybersecurity-15-18814817
x_refsource_MISC
http://flaked.sockpuppet.org/2018/05/16/a-unified-timeline.html
x_refsource_MISC
104162
vdb-entry
x_refsource_BID
https://efail.de
x_refsource_MISC
https://twitter.com/matthew_d_green/status/995996706457243648
x_refsource_MISC
https://www.synology.com/support/security/Synology_SA_18_22
x_refsource_CONFIRM
1040904
vdb-entry
x_refsource_SECTRACK
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now