KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:a:kde:kmail:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "5.5.1"
}
]
},
{
"cpe": "cpe:2.3:a:kde:messagelib:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "5.5.1"
}
]
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"fixed": "5.5.2"
},
{
"fixed": "5.5.2"
}
]
}
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-9604.json"
"2026-04-11T16:44:15Z"
[
{
"signature_version": "v1",
"digest": {
"line_hashes": [
"26936862751056223271378651773350141874",
"147753422659276439829638422992941333413",
"256055254617099371927628159996071252580",
"6237817401237767029496548082185589423"
],
"threshold": 0.9
},
"id": "CVE-2017-9604-1e691798",
"source": "https://github.com/kde/kmail/commit/78c5552be2f00a4ac25bd77ca39386522fca70a8",
"deprecated": false,
"target": {
"file": "src/editor/kmcomposerwin.h"
},
"signature_type": "Line"
},
{
"signature_version": "v1",
"digest": {
"length": 1340.0,
"function_hash": "257727360109239230956837983898494587049"
},
"id": "CVE-2017-9604-3c165c1d",
"source": "https://github.com/kde/kmail/commit/78c5552be2f00a4ac25bd77ca39386522fca70a8",
"deprecated": false,
"target": {
"file": "src/editor/kmcomposerwin.cpp",
"function": "KMComposerWin::slotSendLater"
},
"signature_type": "Function"
},
{
"signature_version": "v1",
"digest": {
"length": 4177.0,
"function_hash": "329420148006121099214417486198642879029"
},
"id": "CVE-2017-9604-91527bf2",
"source": "https://github.com/kde/kmail/commit/78c5552be2f00a4ac25bd77ca39386522fca70a8",
"deprecated": false,
"target": {
"file": "src/editor/kmcomposerwin.cpp",
"function": "KMComposerWin::doSend"
},
"signature_type": "Function"
},
{
"signature_version": "v1",
"digest": {
"line_hashes": [
"171515760466386715851801238677479693481",
"100956914222261329371661719711300125466",
"102414020928253762685753738538812198397",
"33286685259308721839446318719666905468",
"188097591602447983849197220311793201881",
"319182387174062329084136337923299632568",
"36921979096037215443175291460946474118",
"88681689698140011510796676589812913505",
"317625579068653833866580054865005408390",
"126345107536763788961993512739101468109",
"25040293319142026826008149727049811036",
"223294017360101117060230640828457089701",
"324396016245741148738556180156061430484",
"242628843457735989557136813190891846434",
"15709050902440614553125708423259186651",
"190971110931613532423060893732171562942",
"39003264449620868237994001715739632699",
"61962259295180074635088808312496210824"
],
"threshold": 0.9
},
"id": "CVE-2017-9604-b7a46cca",
"source": "https://github.com/kde/kmail/commit/78c5552be2f00a4ac25bd77ca39386522fca70a8",
"deprecated": false,
"target": {
"file": "src/editor/kmcomposerwin.cpp"
},
"signature_type": "Line"
}
]