PT-2021-22086 · Kde · Kde Trojita

Damian Poddebniak

·

Published

2021-08-10

·

Updated

2021-08-20

·

CVE-2021-38372

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions KDE Trojita version 0.7
Description Man-in-the-middle attackers can create new folders because untagged responses from an IMAP server are accepted before STARTTLS.
Recommendations For KDE Trojita version 0.7, consider disabling the acceptance of untagged responses from the IMAP server before STARTTLS as a temporary workaround until a patch is available. Restrict access to folder creation functionality to minimize the risk of exploitation.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-38372

Affected Products

Kde Trojita