Описание
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
fetchmail | fixed | 6.4.22-1 | package | |
fetchmail | no-dsa | bullseye | package | |
fetchmail | no-dsa | buster | package | |
fetchmail | no-dsa | stretch | package |
Примечания
https://www.fetchmail.info/fetchmail-SA-2021-02.txt
EPSS
Процентиль: 30%
0.0011
Низкий
Связанные уязвимости
CVSS3: 5.9
ubuntu
почти 4 года назад
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.
CVSS3: 5.9
redhat
почти 4 года назад
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.
CVSS3: 5.9
nvd
почти 4 года назад
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.
EPSS
Процентиль: 30%
0.0011
Низкий