PT-2017-13830 · Google+3 · Go+3
Simon Rawet
·
Publicado
2017-10-05
·
Atualizado
2024-06-15
·
CVE-2017-15042
CVSS v3.1
5.9
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Go versions prior to 1.8.4
Go versions 1.9.x prior to 1.9.1
Description
An issue exists where the PLAIN authentication scheme is used on network connections not secured with TLS, contrary to the requirements of RFC 4954. This allows a man-in-the-middle SMTP server to obtain the username and password. The
smtp.PlainAuth implementation in Go sends the username and password if a man-in-the-middle SMTP server does not advertise STARTTLS but does advertise that PLAIN auth is acceptable.Recommendations
For Go versions prior to 1.8.4, update to version 1.8.4 or later to resolve the issue.
For Go versions 1.9.x prior to 1.9.1, update to version 1.9.1 or later to resolve the issue.
As a temporary workaround, consider restricting the use of the
smtp.PlainAuth function to only secure connections until a patch is applied.Correção
Cleartext Transmission of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Go
Red Hat