Lucene search

K
cve[email protected]CVE-2014-2567
HistoryMar 21, 2014 - 10:55 a.m.

CVE-2014-2567

2014-03-2110:55:05
CWE-200
web.nvd.nist.gov
20
trojita
cve-2014-2567
openconnectiontask
handlestatehelper
imap
tasks
man-in-the-middle
cleartext
preauth
starttls

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

30.5%

The OpenConnectionTask::handleStateHelper function in Imap/Tasks/OpenConnectionTask.cpp in Trojita before 0.4.1 allows man-in-the-middle attackers to trigger use of cleartext for saving a message into a (1) sent or (2) draft folder via a PREAUTH response that prevents later use of the STARTTLS command.

Affected configurations

NVD
Node
trojita_projecttrojitaRange0.4
OR
trojita_projecttrojitaMatch0.1
OR
trojita_projecttrojitaMatch0.2
OR
trojita_projecttrojitaMatch0.2.9
OR
trojita_projecttrojitaMatch0.2.9.1
OR
trojita_projecttrojitaMatch0.2.9.2
OR
trojita_projecttrojitaMatch0.2.9.3
OR
trojita_projecttrojitaMatch0.2.9.4
OR
trojita_projecttrojitaMatch0.3
OR
trojita_projecttrojitaMatch0.3.90
OR
trojita_projecttrojitaMatch0.3.91
OR
trojita_projecttrojitaMatch0.3.92
OR
trojita_projecttrojitaMatch0.3.93
OR
trojita_projecttrojitaMatch0.3.96

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

30.5%