← Back to CVE List

CVE-2017-17688

Published: 2018-05-16T19:29Z
Last Modified: 2024-11-21T03:18Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification > MITRE Terms of Use apply – see LICENSE‑MITRE.txt