https://seclists.org/oss-sec/2024/q2/174: libksieve (used by kmail/kontact) sent password as username
Published Apr 25, 2024
·Updated
Affected Software
1 affected component
KDE libksieve
Frequently Asked Questions
1
What is the severity of CVE-2024-30639?
The severity of CVE-2024-30639 is classified as high due to the potential exposure of user passwords.
2
How do I fix CVE-2024-30639?
To fix CVE-2024-30639, update to the latest version of KDE libksieve where the vulnerability has been addressed.
3
What impact does CVE-2024-30639 have on user data?
CVE-2024-30639 can lead to unauthorized access to user accounts as passwords are sent improperly as usernames.
4
Who is affected by CVE-2024-30639?
Any user of KDE libksieve, particularly those using kmail/kontact, may be affected by CVE-2024-30639.
5
When was CVE-2024-30639 published?
CVE-2024-30639 was published on April 25, 2024.