Lucene search

K
freebsdFreeBSD36F9AC43-B2AC-11E3-8752-080027EF73EC
HistoryMar 20, 2014 - 12:00 a.m.

mail/trojita -- may leak mail contents (not user credentials) over unencrypted connection

2014-03-2000:00:00
vuxml.freebsd.org
15

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.001 Low

EPSS

Percentile

30.3%

Jan Kundrát reports:

An SSL stripping vulnerability was discovered in Trojitá, a fast Qt
IMAP e-mail client. User’s credentials are never leaked, but if a
user tries to send an e-mail, the automatic saving into the “sent”
or “draft” folders could happen over a plaintext connection even if
the user’s preferences specify STARTTLS as a requirement.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchtrojita< 0.4.1UNKNOWN

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.001 Low

EPSS

Percentile

30.3%

Related for 36F9AC43-B2AC-11E3-8752-080027EF73EC