Lucene search

K
mageiaGentoo FoundationMGASA-2014-0500
HistoryNov 29, 2014 - 11:46 p.m.

Updated geary package fixes security vulnerability

2014-11-2923:46:32
Gentoo Foundation
advisories.mageia.org
7

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.001 Low

EPSS

Percentile

49.7%

Geary before 0.6.3 does not present the user with a warning when a TLS certificate error is detected, which makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted certificate (CVE-2014-5444).

OSVersionArchitecturePackageVersionFilename
Mageia4noarchgeary< 0.6.3-1geary-0.6.3-1.mga4

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.001 Low

EPSS

Percentile

49.7%