Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-50624

Опубликовано: 28 окт. 2024
Источник: debian
EPSS Низкий

Описание

ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL such as http://autoconfig.example.com or http://example.com/.well-known/autoconfig for retrieving the configuration. This is related to kmail-account-wizard.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
kmail-account-wizardfixed4:24.08.0-1experimentalpackage
kmail-account-wizardfixed4:24.12.0-2package
kmail-account-wizardfixed4:22.12.3-1+deb12u1bookwormpackage

Примечания

  • https://bugs.kde.org/show_bug.cgi?id=487882

  • https://invent.kde.org/pim/kmail-account-wizard/-/commit/9784f5ab41c3aff435d4a88afb25585180a62ee4 (v24.07.80)

  • Vulnerable code in src/ispdb/ispdb.cpp

EPSS

Процентиль: 8%
0.0003
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 1 года назад

ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL such as http://autoconfig.example.com or http://example.com/.well-known/autoconfig for retrieving the configuration. This is related to kmail-account-wizard.

CVSS3: 5.9
nvd
больше 1 года назад

ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL such as http://autoconfig.example.com or http://example.com/.well-known/autoconfig for retrieving the configuration. This is related to kmail-account-wizard.

suse-cvrf
больше 1 года назад

Security update for kmail-account-wizard

CVSS3: 5.9
github
больше 1 года назад

ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL such as http://autoconfig.example.com or http://example.com/.well-known/autoconfig for retrieving the configuration. This is related to kmail-account-wizard.

EPSS

Процентиль: 8%
0.0003
Низкий