CVE-2014-2567

The OpenConnectionTask::handleStateHelper function in Imap/Tasks/OpenConnectionTask.cpp in Trojita before 0.4.1 allows man-in-the-middle attackers to trigger use of cleartext for saving a message into a (1) sent or (2) draft folder via a PREAUTH response that prevents later use of the STARTTLS command.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
VendorProductVersion
trojita_projecttrojita
𝑥
≤ 0.4
trojita_projecttrojita
0.1
trojita_projecttrojita
0.2
trojita_projecttrojita
0.2.9
trojita_projecttrojita
0.2.9.1
trojita_projecttrojita
0.2.9.2
trojita_projecttrojita
0.2.9.3
trojita_projecttrojita
0.2.9.4
trojita_projecttrojita
0.3
trojita_projecttrojita
0.3.90
trojita_projecttrojita
0.3.91
trojita_projecttrojita
0.3.92
trojita_projecttrojita
0.3.93
trojita_projecttrojita
0.3.96
𝑥
= Vulnerable software versions