Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2010-4533

Опубликовано: 13 нояб. 2019
Источник: debian

Описание

offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
offlineimapfixed6.3.4-1package
offlineimapno-dsasqueezepackage
offlineimapno-dsalennypackage

Примечания

  • offlineimap uses the "ssl" standard lib in Python, marking the version of offlineimap in wheezy as fixed

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 6 лет назад

offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.

CVSS3: 9.8
nvd
около 6 лет назад

offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.

github
больше 3 лет назад

offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.