PT-2007-2942 · Gnome+6 · Balsa+8

Publicado

2007-04-16

·

Atualizado

2024-06-15

·

CVE-2007-1558

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Thunderbird versions 1.x prior to 1.5.0.12 Thunderbird versions 2.x prior to 2.0.0.4 Evolution (affected versions not specified) mutt (affected versions not specified) fetchmail versions prior to 6.3.8 SeaMonkey versions 1.0.x prior to 1.0.9 SeaMonkey versions 1.1.x prior to 1.1.2 Balsa version 2.3.16 and earlier Mailfilter versions prior to 0.8.2
Description The APOP protocol is susceptible to man-in-the-middle (MITM) attacks, allowing remote attackers to guess the first 3 characters of a password. This is achieved through crafted message IDs and MD5 collisions.
Recommendations For Thunderbird versions 1.x, update to version 1.5.0.12 or later. For Thunderbird versions 2.x, update to version 2.0.0.4 or later. For fetchmail, update to version 6.3.8 or later. For SeaMonkey versions 1.0.x, update to version 1.0.9 or later. For SeaMonkey versions 1.1.x, update to version 1.1.2 or later. For Balsa, update to a version later than 2.3.16. For Mailfilter, update to version 0.8.2 or later. For Evolution and mutt, at the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1558
DSA-1300-1
DSA-1305-1
DTSA-46-1
DTSA-47-1
HPSBUX02153
OPENSUSE-SU-2024:10686-1
OPENSUSE-SU-2024:10753-1
OPENSUSE-SU-2024:11069-1
OPENSUSE-SU-2024:11615-1
RHSA-2007:0344
RHSA-2007:0353
RHSA-2007:0385
RHSA-2007:0386
RHSA-2007:0401
RHSA-2007:0402
RHSA-2007_0344
RHSA-2007_0353
RHSA-2007_0385
RHSA-2007_0386
RHSA-2007_0401
RHSA-2007_0402
RHSA-2009:1140
RHSA-2009_1140

Produtos afetados

Balsa
Evolution
Hp-Ux
Mailfilter
Red Hat
Seamonkey
Thunderbird
Fetchmail
Mutt