LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a meddler-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libetpan | Oct 13, 2020 | Jul 27, 2020 |
| Debian | — | Upgrade libetpan | Aug 17, 2020 | Jul 27, 2020 |
| Gentoo Linux | — | Upgrade net-libs/libetpan. | Jul 29, 2020 | Jul 27, 2020 |
| Suse | — | Upgrade libetpan20Upgrade libetpan-devel | Sep 20, 2020 | Jul 27, 2020 |
| Ubuntu | — | Upgrade libetpan-devUpgrade libetpan17 | Oct 23, 2020 | Jul 27, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub