KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain sensitive information by sniffing the network.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1243777 | Issue Tracking Patch Third Party Advisory VDB Entry |
https://bugs.kde.org/show_bug.cgi?id=340312 | Issue Tracking Patch Vendor Advisory |
http://www.securityfocus.com/bid/75986 | Third Party Advisory VDB Entry |
http://www.openwall.com/lists/oss-security/2015/07/16/10 | Mailing List Patch Third Party Advisory VDB Entry |
Configurations
Information
Published : 2017-09-27 18:29
Updated : 2017-10-06 12:13
NVD link : CVE-2014-8878
Mitre link : CVE-2014-8878
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
kde
- kmail