CVE-2017-9604
KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.29% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-311
- Affected
- kde/kmail · kde/messagelib
- Source
- cve@mitre.org
References
- https://commits.kde.org/kmail/78c5552be2f00a4ac25bd77ca39386522fca70a8Mailing List, Patch, Tool Signature
- https://commits.kde.org/messagelib/c54706e990bbd6498e7b1597ec7900bc809e8197Mailing List, Patch, Tool Signature
- https://commits.kde.org/kmail/78c5552be2f00a4ac25bd77ca39386522fca70a8Mailing List, Patch, Tool Signature
- https://commits.kde.org/messagelib/c54706e990bbd6498e7b1597ec7900bc809e8197Mailing List, Patch, Tool Signature
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.