plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
CVSS Details
- CVSS 3.1 Base Score: 7.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade claws-mail | Jul 30, 2024 | Oct 15, 2014 |
| Suse | — | Upgrade claws-mail-develUpgrade claws-mail-debuginfoUpgrade claws-mail-debugsourceUpgrade claws-mail-langUpgrade claws-mail | Dec 18, 2015 | Oct 14, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub