CVE-2014-7273: Medium severity getmail vulnerability
The IMAP-over-SSL implementation in getmail 4.0.0 through 4.43.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof IMAP servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7273?
CVE-2014-7273 is classified as a high severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2014-7273?
To fix CVE-2014-7273, upgrade your Getmail version to at least 4.43.1 or later, which includes SSL certificate validation.
What vulnerability does CVE-2014-7273 expose?
CVE-2014-7273 exposes a vulnerability that allows attackers to spoof IMAP servers by exploiting SSL certificate verification issues.
What versions of Getmail are affected by CVE-2014-7273?
CVE-2014-7273 affects Getmail versions 4.0.0 through 4.43.0.
Who is impacted by CVE-2014-7273?
Users of affected versions of Getmail who rely on IMAP-over-SSL for email retrieval are at risk from CVE-2014-7273.