CVE-2016-10727

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
Affected Products (NVD)
VendorProductVersion
canonicalubuntu_linux
14.04
canonicalubuntu_linux
16.04
gnomeevolution
𝑥
< 3.21.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
evolution-data-server
bookworm
3.46.4-2
fixed
bullseye
3.38.3-1+deb11u2
fixed
sid
3.54.1-1
fixed
trixie
3.54.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
evolution-data-server
artful
not-affected
bionic
not-affected
trusty
Fixed 3.10.4-0ubuntu1.6
released
xenial
Fixed 3.18.5-1ubuntu1.1
released
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
evolution-data-server
RHEL 7
0:3.12.11-37.el7
fixed
evolution-data-server-devel
RHEL 7
0:3.12.11-37.el7
fixed
evolution-data-server-doc
RHEL 7
0:3.12.11-37.el7
fixed
evolution-ews
RHEL 7
0:3.12.11-9.el7
fixed
evolution-mapi
RHEL 7
0:3.12.10-5.el7
fixed
evolution-mapi-devel
RHEL 7
0:3.12.10-5.el7
fixed
openchange
RHEL 7
0:2.3-2.el7
fixed
openchange-client
RHEL 7
0:2.3-2.el7
fixed
openchange-devel
RHEL 7
0:2.3-2.el7
fixed
openchange-devel-docs
RHEL 7
0:2.3-2.el7
fixed