HIGH7.5
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:P/A:NCVSS 3.xHIGH 7.5
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NReferences
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00042.html
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00002.html
- https://bugs.debian.org/939702
- https://github.com/lefcha/imapfilter/issues/142
- https://lists.debian.org/debian-lts-announce/2019/10/msg00040.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GBNDFMAIUA6PQMV2P6OKIP7JZQEWX7D2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IQUH2TOCNEST7JB2RJVVJT3RZS5XZCFZ/
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00042.html
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00002.html
- https://bugs.debian.org/939702
- https://github.com/lefcha/imapfilter/issues/142
- https://lists.debian.org/debian-lts-announce/2019/10/msg00040.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GBNDFMAIUA6PQMV2P6OKIP7JZQEWX7D2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IQUH2TOCNEST7JB2RJVVJT3RZS5XZCFZ/