The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2007"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2010"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2013"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2016"
}
]
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-17689.json"