4.3

CVE-2014-2014

imapsync before 1.584, when running with the --tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain credentials by sniffing the network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Imapsync ProjectImapsync Version <= 1.580
Imapsync ProjectImapsync Version1.53
Imapsync ProjectImapsync Version1.500
Imapsync ProjectImapsync Version1.504
Imapsync ProjectImapsync Version1.508
Imapsync ProjectImapsync Version1.516
Imapsync ProjectImapsync Version1.518
Imapsync ProjectImapsync Version1.525
Imapsync ProjectImapsync Version1.542
Imapsync ProjectImapsync Version1.547
Imapsync ProjectImapsync Version1.554
Imapsync ProjectImapsync Version1.558
Imapsync ProjectImapsync Version1.564
Imapsync ProjectImapsync Version1.567
Imapsync ProjectImapsync Version1.569
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.54% 0.716
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.mandriva.com/security/advisories?name=MDVSA-2014:060
http://seclists.org/oss-sec/2014/q1/367
http://seclists.org/oss-sec/2014/q1/378
Patch
http://www.linux-france.org/prj/imapsync_list/msg01907.html
http://www.linux-france.org/prj/imapsync_list/msg01910.html
https://bugs.mageia.org/show_bug.cgi?id=12770
https://github.com/imapsync/imapsync/issues/15
https://lists.fedoraproject.org/pipermail/package-announce/2014-February/128293.html