[gelöst] CVE-Systematik ist mir unklar
Verfasst: 20.05.2018 06:14:27
Hallo debianforum.de,
Ich sehe bei der CVE-Systematik nicht durch:
/usr/share/doc/thunderbird/changelog.Debian.gz:
Mit freundlichen Grüßen
bullgard
Ich sehe bei der CVE-Systematik nicht durch:
/usr/share/doc/thunderbird/changelog.Debian.gz:
- Warum schreibt aber http://cve.mitre.org/cgi-bin/cvekey.cgi ... -2018-5185:…[ Carsten Schoenert ] … CVE-2018-5185: Leaking plaintext through HTML form (aka Efail).
? und http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=Efail:CVE-2018-5185 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
?CVE-2017-17689 The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
CVE-2017-17688 ** DISPUTED ** The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification
Mit freundlichen Grüßen
bullgard