The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
Link | Tags |
---|---|
https://news.ycombinator.com/item?id=17066419 | issue tracking third party advisory |
https://pastebin.com/gNCc8aYm | third party advisory |
http://www.securityfocus.com/bid/104165 | vdb entry third party advisory |
https://twitter.com/matthew_d_green/status/996371541591019520 | third party advisory |
https://efail.de | exploit third party advisory mitigation |
https://www.synology.com/support/security/Synology_SA_18_22 | third party advisory |