PT-2014-4788 · Claws Mail Team+1 · Claws Mail+1
Marcus Meissner
·
Publicado
2014-05-26
·
Atualizado
2018-10-30
·
CVE-2014-2576
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Claws Mail versions prior to 3.10.0
Description
The issue makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks by disabling the
CURLOPT SSL VERIFYHOST check for CN or SAN host name fields in the feed.c plugin.Recommendations
For versions prior to 3.10.0, update to version 3.10.0 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Claws Mail