CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
82.5%
camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME
evolution-data-server before 3.21.2 proceeds with cleartext data containing
a password if the client wishes to use STARTTLS but the server will not use
STARTTLS, which makes it easier for remote attackers to obtain sensitive
information by sniffing the network. The server code was intended to report
an error and not proceed, but the code was written incorrectly.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 14.04 | noarch | evolution-data-server | < 3.10.4-0ubuntu1.6 | UNKNOWN |
ubuntu | 16.04 | noarch | evolution-data-server | < 3.18.5-1ubuntu1.1 | UNKNOWN |
github.com/GNOME/evolution-data-server/releases/tag/EVOLUTION_DATA_SERVER_3_21_2
gitlab.gnome.org/GNOME/evolution-data-server/blob/master/NEWS#L1022
launchpad.net/bugs/cve/CVE-2016-10727
nvd.nist.gov/vuln/detail/CVE-2016-10727
security-tracker.debian.org/tracker/CVE-2016-10727
ubuntu.com/security/notices/USN-3724-1
www.cve.org/CVERecord?id=CVE-2016-10727
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
82.5%