PT-2007-2942 · Gnome+6 · Balsa+8

Published

2007-04-16

·

Updated

2024-06-15

·

CVE-2007-1558

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Thunderbird versions 1.x prior to 1.5.0.12 Thunderbird versions 2.x prior to 2.0.0.4 Evolution (affected versions not specified) mutt (affected versions not specified) fetchmail versions prior to 6.3.8 SeaMonkey versions 1.0.x prior to 1.0.9 SeaMonkey versions 1.1.x prior to 1.1.2 Balsa version 2.3.16 and earlier Mailfilter versions prior to 0.8.2
Description The APOP protocol is susceptible to man-in-the-middle (MITM) attacks, allowing remote attackers to guess the first 3 characters of a password. This is achieved through crafted message IDs and MD5 collisions.
Recommendations For Thunderbird versions 1.x, update to version 1.5.0.12 or later. For Thunderbird versions 2.x, update to version 2.0.0.4 or later. For fetchmail, update to version 6.3.8 or later. For SeaMonkey versions 1.0.x, update to version 1.0.9 or later. For SeaMonkey versions 1.1.x, update to version 1.1.2 or later. For Balsa, update to a version later than 2.3.16. For Mailfilter, update to version 0.8.2 or later. For Evolution and mutt, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1558
DSA-1300-1
DSA-1305-1
DTSA-46-1
DTSA-47-1
HPSBUX02153
OPENSUSE-SU-2024:10686-1
OPENSUSE-SU-2024:10753-1
OPENSUSE-SU-2024:11069-1
OPENSUSE-SU-2024:11615-1
RHSA-2007:0344
RHSA-2007:0353
RHSA-2007:0385
RHSA-2007:0386
RHSA-2007:0401
RHSA-2007:0402
RHSA-2007_0344
RHSA-2007_0353
RHSA-2007_0385
RHSA-2007_0386
RHSA-2007_0401
RHSA-2007_0402
RHSA-2009:1140
RHSA-2009_1140

Affected Products

Balsa
Evolution
Hp-Ux
Mailfilter
Red Hat
Seamonkey
Thunderbird
Fetchmail
Mutt