Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cq85-qr6h-4x5p

Опубликовано: 03 мая 2022
Источник: github
Github: Не прошло ревью

Описание

fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances occur, which allows remote attackers to obtain sensitive information via man-in-the-middle (MITM) attacks.

fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances occur, which allows remote attackers to obtain sensitive information via man-in-the-middle (MITM) attacks.

Ссылки

EPSS

Процентиль: 91%
0.06446
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 18 лет назад

fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances occur, which allows remote attackers to obtain sensitive information via man-in-the-middle (MITM) attacks.

redhat
больше 18 лет назад

fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances occur, which allows remote attackers to obtain sensitive information via man-in-the-middle (MITM) attacks.

nvd
больше 18 лет назад

fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances occur, which allows remote attackers to obtain sensitive information via man-in-the-middle (MITM) attacks.

debian
больше 18 лет назад

fetchmail before 6.3.6-rc4 does not properly enforce TLS and may trans ...

EPSS

Процентиль: 91%
0.06446
Низкий

Дефекты

CWE-20