Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3hf7-p43g-vpv6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. This allows e-mail messages and user credentials to be sent to the MitM attacker.

In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. This allows e-mail messages and user credentials to be sent to the MitM attacker.

EPSS

Процентиль: 55%
0.00322
Низкий

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 5.9
nvd
больше 4 лет назад

In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. This allows e-mail messages and user credentials to be sent to the MitM attacker.

EPSS

Процентиль: 55%
0.00322
Низкий

Дефекты

CWE-77