CVE-2017-7229 Information

Description

PGP/MIME encrypted messages injected into a Vaultive O365 (before 4.5.21) frontend via IMAP or SMTP have their Content-Type changed from ‘Content-Type: multipart/encrypted; protocol=\application/pgp-encrypted; boundary=\abc123abc123' to ‘Content-Type: text/plain’ - this results in the encrypted message being structured in such a way that most PGP/MIME-capable mail user agents are unable to decrypt it cleanly. The outcome is that encrypted mail passing through this device does not work (Denial of Service) and a common real-world consequence is a request to resend the mail in the clear (Information Disclosure).

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Reference

https://gist.github.com/dkg/a1998c861bf2430e0d01d586905b11cb

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

HIGH

Base Severity

9.1

Share on: