CVE Vulnerabilities

CVE-2014-8878

Published: Sep 28, 2017 | Modified: Apr 20, 2025
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

KDE KMail does not encrypt attachments in emails when automatic encryption is enabled, which allows remote attackers to obtain sensitive information by sniffing the network.

Affected Software

NameVendorStart VersionEnd Version
KmailKde4.11.5 (including)4.11.5 (including)
KdepimUbuntuesm-infra-legacy/trusty*
KdepimUbuntutrusty*
KdepimUbuntutrusty/esm*
KdepimUbuntuupstream*
KdepimUbuntuutopic*

References