First published: Wed Oct 08 2014(Updated: )
The IMAP-over-SSL implementation in getmail 4.0.0 through 4.43.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof IMAP servers and obtain sensitive information via a crafted certificate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Getmail Getmail | =4.0 | |
Getmail Getmail | =4.0.0_b10 | |
Getmail Getmail | =4.0.1 | |
Getmail Getmail | =4.0.2 | |
Getmail Getmail | =4.0.3 | |
Getmail Getmail | =4.0.4 | |
Getmail Getmail | =4.0.5 | |
Getmail Getmail | =4.0.6 | |
Getmail Getmail | =4.0.7 | |
Getmail Getmail | =4.0.8 | |
Getmail Getmail | =4.0.9 | |
Getmail Getmail | =4.0.10 | |
Getmail Getmail | =4.0.11 | |
Getmail Getmail | =4.0.12 | |
Getmail Getmail | =4.0.13 | |
Getmail Getmail | =4.1 | |
Getmail Getmail | =4.1.1 | |
Getmail Getmail | =4.1.2 | |
Getmail Getmail | =4.1.3 | |
Getmail Getmail | =4.1.4 | |
Getmail Getmail | =4.1.5 | |
Getmail Getmail | =4.2.0 | |
Getmail Getmail | =4.3.0 | |
Getmail Getmail | =4.4.0 | |
Getmail Getmail | =4.5.0 | |
Getmail Getmail | =4.6.0 | |
Getmail Getmail | =4.7.0 | |
Getmail Getmail | =4.8.0 | |
Getmail Getmail | =4.9.0 | |
Getmail Getmail | =4.10.0 | |
Getmail Getmail | =4.11.0 | |
Getmail Getmail | =4.12.0 | |
Getmail Getmail | =4.13.0 | |
Getmail Getmail | =4.14.0 | |
Getmail Getmail | =4.15.0 | |
Getmail Getmail | =4.16.0 | |
Getmail Getmail | =4.17.0 | |
Getmail Getmail | =4.18.0 | |
Getmail Getmail | =4.19.0 | |
Getmail Getmail | =4.20.0 | |
Getmail Getmail | =4.21.0 | |
Getmail Getmail | =4.22.0 | |
Getmail Getmail | =4.23.0 | |
Getmail Getmail | =4.24.0 | |
Getmail Getmail | =4.25.0 | |
Getmail Getmail | =4.26.0 | |
Getmail Getmail | =4.27.0 | |
Getmail Getmail | =4.28.0 | |
Getmail Getmail | =4.29.0 | |
Getmail Getmail | =4.30.0 | |
Getmail Getmail | =4.31.0 | |
Getmail Getmail | =4.32.0 | |
Getmail Getmail | =4.33.0 | |
Getmail Getmail | =4.34.0 | |
Getmail Getmail | =4.35.0 | |
Getmail Getmail | =4.36.0 | |
Getmail Getmail | =4.37.0 | |
Getmail Getmail | =4.38.0 | |
Getmail Getmail | =4.39.0 | |
Getmail Getmail | =4.40.0 | |
Getmail Getmail | =4.41.0 | |
Getmail Getmail | =4.42.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.