CVE-2020-14928: Medium severity evolution data server vulnerability
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-14928?
CVE-2020-14928 is a vulnerability in evolution-data-server (eds) through 3.36.3 that affects SMTP and POP3 due to a STARTTLS buffering issue.
What is the severity of CVE-2020-14928?
The severity of CVE-2020-14928 is medium with a CVSS score of 5.9.
Which software versions are affected by CVE-2020-14928?
The affected software versions are evolution-data-server 3.36.3-0ubuntu1.1, 3.28.5-0ubuntu0.18.04.3, 3.36.4-1, and 3.18.5-1ubuntu1.3.
How can I fix CVE-2020-14928?
To fix CVE-2020-14928, update evolution-data-server to version 3.36.3-0ubuntu1.1, 3.28.5-0ubuntu0.18.04.3, 3.36.4-1, or 3.18.5-1ubuntu1.3.
Are there any references for CVE-2020-14928?
Yes, you can find references for CVE-2020-14928 at the following links: [1] https://bugzilla.suse.com/show_bug.cgi?id=1173910, [2] https://gitlab.gnome.org/GNOME//evolution-data-server/commit/ba82be72cfd427b5d72ff21f929b3a6d8529c4df, [3] https://gitlab.gnome.org/GNOME/evolution-data-server/-/commit/f404f33fb01b23903c2bbb16791c7907e457fbac.