Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-29547

Опубликовано: 29 мая 2023
Источник: debian

Описание

An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands into an encrypted user session. This can lead to credential disclosure.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
citadelremovedpackage
citadelignoredbusterpackage
citadelpostponedstretchpackage

Примечания

  • https://uncensored.citadel.org/readfwd?go=Citadel Security?view=0?start_reading_at=2099264259#2099264259

  • https://nostarttls.secvuln.info/

  • CVE-2020-29547 and CVE-2021-37845 seem like dupes

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 2 лет назад

An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands into an encrypted user session. This can lead to credential disclosure.

CVSS3: 5.9
nvd
больше 2 лет назад

An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands into an encrypted user session. This can lead to credential disclosure.

CVSS3: 5.9
github
больше 2 лет назад

An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands into an encrypted user session. This can lead to credential disclosure.