oss-sec mailing list archives
Re: PGP/MIME and S/MIME mail clients vulnerabilities
From: Florian Weimer <fw () deneb enyo de>
Date: Tue, 22 May 2018 21:06:53 +0200
* Matthew Fernandez:
I presume what Florian is asking about is Content-ID links [0]. One purpose of CID links is to include images as a message part and then reference them from the HTML email content. I would think a CID URL would not be immediately vulnerable to the “direct exfiltration” attack because it shouldn’t result in a network fetch; just a lookup locally. However, RFC 2392 requires the IDs to be “globally unique” and some mail clients (e.g. iOS Mail) take the RFC at its word and render images from CID URLs that reference content included in entirely distinct emails in your mailbox. Perhaps the attacker can hide their payload within a message part with the chosen ID included in another email.
Or they can alter the displayed content of a signed message with a colliding cid: URL, assuming the ones generated by the original client are not unpredictable (and you might actually have many tries within the same crafted message). There could also be some automated exfiltration angles, but those probably rely on client HTML rendering bugs, so they don't really count.
Current thread:
- Re: PGP/MIME and S/MIME mail clients vulnerabilities, (continued)
- Re: PGP/MIME and S/MIME mail clients vulnerabilities Christian Brabandt (May 14)
- Re: PGP/MIME and S/MIME mail clients vulnerabilities Yves-Alexis Perez (May 14)
- Re: PGP/MIME and S/MIME mail clients vulnerabilities Brian May (May 15)
- Re: PGP/MIME and S/MIME mail clients vulnerabilities Yves-Alexis Perez (May 15)
- Re: PGP/MIME and S/MIME mail clients vulnerabilities Leo Gaspard (May 15)
- Re: PGP/MIME and S/MIME mail clients vulnerabilities Brian May (May 16)
- Re: PGP/MIME and S/MIME mail clients vulnerabilities Brian May (May 16)
- Re: PGP/MIME and S/MIME mail clients vulnerabilities Yves-Alexis Perez (May 14)
- Re: PGP/MIME and S/MIME mail clients vulnerabilities Christian Brabandt (May 14)
- Re: PGP/MIME and S/MIME mail clients vulnerabilities Yves-Alexis Perez (May 16)
- Re: PGP/MIME and S/MIME mail clients vulnerabilities Matthew Fernandez (May 16)
- Re: PGP/MIME and S/MIME mail clients vulnerabilities Florian Weimer (May 22)