CVE-2014-2567
21.03.2014, 10:55
The OpenConnectionTask::handleStateHelper function in Imap/Tasks/OpenConnectionTask.cpp in Trojita before 0.4.1 allows man-in-the-middle attackers to trigger use of cleartext for saving a message into a (1) sent or (2) draft folder via a PREAUTH response that prevents later use of the STARTTLS command.Enginsight
Vendor | Product | Version |
---|---|---|
trojita_project | trojita | 𝑥 ≤ 0.4 |
trojita_project | trojita | 0.1 |
trojita_project | trojita | 0.2 |
trojita_project | trojita | 0.2.9 |
trojita_project | trojita | 0.2.9.1 |
trojita_project | trojita | 0.2.9.2 |
trojita_project | trojita | 0.2.9.3 |
trojita_project | trojita | 0.2.9.4 |
trojita_project | trojita | 0.3 |
trojita_project | trojita | 0.3.90 |
trojita_project | trojita | 0.3.91 |
trojita_project | trojita | 0.3.92 |
trojita_project | trojita | 0.3.93 |
trojita_project | trojita | 0.3.96 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References