Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia: 2021-0208 Moderate: KMail Attachment Decryption Risk

mageia
Calendar Grey May 7, 2021
Dist Mageia Esm H88
Revised messagelib modules resolve a vulnerability, permitting exposed data to be retrieved from afar.
Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g

Summary

Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g. an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. This is not easily noticeable by the user because KMail does not display the decrypted content.
With a specially crafted message a user could be tricked into decrypting an encrypted message and then deleting an attachment attached to this message. If the attacker has access to the messages stored on the email server, then the attacker could read the decrypted content of the encrypted message (CVE-2021-31855).

References

- https://bugs.mageia.org/show_bug.cgi?id=28861

- https://kde.org/info/security/advisory-20210429-1.txt

- https://www.cve.org/CVERecord?id=CVE-2021-31855

Resolution

SRPMS

- 8/core/messagelib-20.12.0-1.1.mga8

- 7/core/messagelib-19.04.0-1.2.mga7

Publication date: 07 May 2021
URL: https://advisories.mageia.org/MGASA-2021-0208.html
Type: security
CVE: CVE-2021-31855

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here