Oval Definition:oval:org.opensuse.security:def:202131855
Revision Date:2022-06-30Version:1
Title:CVE-2021-31855
Description:

KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. With a crafted message, a user could be tricked into decrypting an encrypted message and then deleting an attachment attached to this message. If the attacker has access to the messages stored on the email server, then the attacker could read the decrypted content of the encrypted message. This occurs in ViewerPrivate::deleteAttachment in messageviewer/src/viewer/viewer_p.cpp.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2021-31855
SUSE CVE-2021-31855
Platform(s):openSUSE Leap 15.4
openSUSE Tumbleweed
Product(s):
Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • messagelib-21.08.1-1.2 is installed
  • OR messagelib-devel-21.08.1-1.2 is installed
  • OR messagelib-lang-21.08.1-1.2 is installed
  • Definition Synopsis
  • openSUSE Leap 15.4 is installed
  • AND Package Information
  • messagelib-21.12.3-bp154.1.22 is installed
  • AND messagelib is signed with openSUSE key
  • OR
  • messagelib-lang-21.12.3-bp154.1.22 is installed
  • AND messagelib-lang is signed with openSUSE key
  • BACK