UBUNTU-CVE-2021-31855

Source
https://ubuntu.com/security/CVE-2021-31855
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-31855.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2021-31855
Related
Published
2021-06-02T16:15:00Z
Modified
2024-10-15T14:08:09Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. With a crafted message, a user could be tricked into decrypting an encrypted message and then deleting an attachment attached to this message. If the attacker has access to the messages stored on the email server, then the attacker could read the decrypted content of the encrypted message. This occurs in ViewerPrivate::deleteAttachment in messageviewer/src/viewer/viewer_p.cpp.

References

Affected packages

Ubuntu:Pro:18.04:LTS / kdepim4

Package

Name
kdepim4
Purl
pkg:deb/ubuntu/kdepim4?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4:4.*

4:4.14.10-7

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / kf5-messagelib

Package

Name
kf5-messagelib
Purl
pkg:deb/ubuntu/kf5-messagelib?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4:17.*

4:17.04.3-0ubuntu1
4:17.04.3-0ubuntu2
4:17.08.3-0ubuntu1
4:17.08.3-0ubuntu2
4:17.12.2-0ubuntu3
4:17.12.3-0ubuntu2
4:17.12.3-0ubuntu3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / kf5-messagelib

Package

Name
kf5-messagelib
Purl
pkg:deb/ubuntu/kf5-messagelib?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4:19.*

4:19.04.3-0ubuntu1
4:19.04.3-0ubuntu2
4:19.12.3-0ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / kf5-messagelib

Package

Name
kf5-messagelib
Purl
pkg:deb/ubuntu/kf5-messagelib?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4:21.*

4:21.08.1-0ubuntu1
4:21.08.3-0ubuntu2
4:21.11.80-0ubuntu1
4:21.11.90-0ubuntu1
4:21.12.0-0ubuntu1
4:21.12.1-0ubuntu1
4:21.12.2-0ubuntu1
4:21.12.3-0ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / kf5-messagelib

Package

Name
kf5-messagelib
Purl
pkg:deb/ubuntu/kf5-messagelib?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4:23.*

4:23.08.5-0ubuntu4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / kf5-messagelib

Package

Name
kf5-messagelib
Purl
pkg:deb/ubuntu/kf5-messagelib?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4:23.*

4:23.08.1-0ubuntu1
4:23.08.2-0ubuntu1
4:23.08.3-0ubuntu1
4:23.08.4-0ubuntu1
4:23.08.5-0ubuntu1
4:23.08.5-0ubuntu3
4:23.08.5-0ubuntu4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}