Back to search
CVE-2014-2014
Published: Apr 18, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
imapsync before 1.584, when running with the --tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain credentials by sniffing the network.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20140218 Re: CVE request: "imapsync ignores the --tls switch and sends my authentication plaintext."
mailing-list
x_refsource_MLIST
[oss-security] 20140217 CVE request: "imapsync ignores the --tls switch and sends my authentication plaintext."
mailing-list
x_refsource_MLIST
FEDORA-2014-2505
vendor-advisory
x_refsource_FEDORA
[imapsync_list] 20140120 Re: [imapsync] STARTTLS support (#15)
mailing-list
x_refsource_MLIST
https://github.com/imapsync/imapsync/issues/15
x_refsource_CONFIRM
https://bugs.mageia.org/show_bug.cgi?id=12770
x_refsource_CONFIRM
MDVSA-2014:060
vendor-advisory
x_refsource_MANDRIVA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now