camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade evolution-data-server | Feb 20, 2019 | Jul 20, 2018 |
| Ubuntu | — | Upgrade libcamel-1.2-54Upgrade libcamel-1.2-45Upgrade libebackend-1.2-10Upgrade evolution-data-serverUpgrade libebackend-1.2-7Upgrade libedataserver-1.2-18Upgrade evolution-data-server-commonUpgrade libedataserver-1.2-21 | Aug 7, 2018 | Jul 20, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub