PT-2019-6588 · Offlineimap · Offlineimap

Jan Lieskovsky

·

Publicado

2019-11-13

·

Atualizado

2020-08-18

·

CVE-2010-4533

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions offlineimap versions prior to 6.3.4
Description The issue concerns the use of the SSL v2 protocol, which has multiple security deficiencies. Although offlineimap added support for SSL server certificate validation before version 6.3.4, it is still possible to use the flawed SSL v2 protocol.
Recommendations For versions prior to 6.3.4, update to version 6.3.4 or later to mitigate the risk associated with the use of the SSL v2 protocol.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-4533

Produtos afetados

Offlineimap