{"id":"CVE-2017-17688","details":"The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification","modified":"2026-03-15T22:24:06.120647Z","published":"2018-05-16T19:29:00.223Z","related":["openSUSE-SU-2018:1329-1","openSUSE-SU-2018:1330-1","openSUSE-SU-2024:10736-1"],"references":[{"type":"ADVISORY","url":"http://flaked.sockpuppet.org/2018/05/16/a-unified-timeline.html"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1040904"},{"type":"ADVISORY","url":"https://lists.gnupg.org/pipermail/gnupg-users/2018-May/060334.html"},{"type":"ADVISORY","url":"https://twitter.com/matthew_d_green/status/995996706457243648"},{"type":"ADVISORY","url":"https://www.synology.com/support/security/Synology_SA_18_22"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/104162"},{"type":"REPORT","url":"https://news.ycombinator.com/item?id=17066419"},{"type":"REPORT","url":"https://protonmail.com/blog/pgp-vulnerability-efail"},{"type":"REPORT","url":"https://www.patreon.com/posts/cybersecurity-15-18814817"},{"type":"EVIDENCE","url":"https://efail.de"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-17688.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"2007"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}