[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3091-1 getmail4 -- getmail4

ID: oval:org.secpod.oval:def:601860Date: (C)2014-12-15   (M)2021-09-30
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in getmail4, a mail retriever with support for POP3, IMAP4 and SDPS, that could allow man-in-the-middle attacks. CVE-2014-7273 The IMAP-over-SSL implementation in getmail 4.0.0 through 4.43.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof IMAP servers and obtain sensitive information via a crafted certificate. CVE-2014-7274 The IMAP-over-SSL implementation in getmail 4.44.0 does not verify that the server hostname matches a domain name in the subject"s Common Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof IMAP servers and obtain sensitive information via a crafted certificate from a recognized Certification Authority. CVE-2014-7275 The POP3-over-SSL implementation in getmail 4.0.0 through 4.44.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof POP3 servers and obtain sensitive information via a crafted certificate.

Platform:
Debian 7.0
Product:
getmail4
Reference:
DSA-3091-1
CVE-2014-7273
CVE-2014-7274
CVE-2014-7275
CVE    3
CVE-2014-7273
CVE-2014-7274
CVE-2014-7275
CPE    2
cpe:/a:getmail:getmail:4
cpe:/o:debian:debian_linux:7.x

© SecPod Technologies