#VU52766 Information disclosure in messagelib and kmail - CVE-2021-31855

 

#VU52766 Information disclosure in messagelib and kmail - CVE-2021-31855

Published: April 29, 2021


Vulnerability identifier: #VU52766
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-31855
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
messagelib
kmail
Software vendor:
KDE.org

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the way messagelib in KDE KMail deletes attachments of encrypted messages on a remote server (e.g. an IMAP server). A remote attacker can send a victim a specially crafted encrypted message and trick the victim into deleting an attachments from such message. If the attacker has access to the messages stored on the email server, then the attacker could read the decrypted content of the encrypted message.


Remediation

Install updates from vendor's website.

External links