Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23791
HistoryApr 10, 2020 - 12:36 a.m.

Man-in-the-Middle (MitM)

2020-04-1000:36:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

EPSS

0.001

Percentile

51.1%

fetchmail is vulnerable to man-in-the-middle attack. It was discovered that fetchmail is affected by the previously published β€œnull prefix attack”, caused by incorrect handling of NULL characters in X.509 certificates. If an attacker is able to get a carefully-crafted certificate signed by a trusted Certificate Authority, the attacker could use the certificate during a man-in-the-middle attack and potentially confuse fetchmail into accepting it by mistake.

References