### [CVE-2017-17688](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17688) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen) ### Description The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification ### POC #### Reference - https://www.patreon.com/posts/cybersecurity-15-18814817 #### Github - https://github.com/badigervijay/AI-Based-Threat-Intelligence-Platform - https://github.com/giterlizzi/secdb-feeds - https://github.com/hannob/pgpbugs - https://github.com/jaads/Efail-malleability-gadget-exploit