Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27794
HistoryNov 05, 2020 - 3:10 a.m.

TLS Response Injection

2020-11-0503:10:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
vulnerability
tls
response injection
evolution-data-server
starttls buffering
smtp
pop3
software

EPSS

0.004

Percentile

74.6%

evolution-data-server is vulnerable to TLS response injection. When a server sends a ‘begin TLS’ response, eds reads additional data and evaluates it in a TLS context, aka “response injection” causing a STARTTLS buffering issue that affects SMTP and POP3.