CVE Vulnerabilities

CVE-2014-8878

Published: Sep 28, 2017 | Modified: Oct 06, 2017
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM

KDE KMail does not encrypt attachments in emails when automatic encryption is enabled, which allows remote attackers to obtain sensitive information by sniffing the network.

Affected Software

Name Vendor Start Version End Version
Kmail Kde 4.11.5 (including) 4.11.5 (including)
Kdepim Ubuntu esm-infra-legacy/trusty *
Kdepim Ubuntu trusty *
Kdepim Ubuntu trusty/esm *
Kdepim Ubuntu upstream *
Kdepim Ubuntu utopic *

References