Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10727

Опубликовано: 10 мая 2016
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.

Отчет

This issue did not affect the versions of evolution-data-server as shipped with Red Hat Enterprise Linux 5 and 6 as they did not include the vulnerable code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5evolution-data-serverNot affected
Red Hat Enterprise Linux 6evolution-data-serverNot affected
Red Hat Enterprise Linux 8evolution-data-serverNot affected
Red Hat Enterprise Linux 7evolution-data-serverFixedRHBA-2016:220603.11.2016
Red Hat Enterprise Linux 7evolution-ewsFixedRHBA-2016:220603.11.2016
Red Hat Enterprise Linux 7evolution-mapiFixedRHBA-2016:220603.11.2016
Red Hat Enterprise Linux 7openchangeFixedRHBA-2016:220603.11.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-393->CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=1609916evolution-data-server: IMAPx Component Information Disclosure

EPSS

Процентиль: 77%
0.01022
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.

CVSS3: 9.8
nvd
больше 7 лет назад

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.

CVSS3: 9.8
debian
больше 7 лет назад

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in G ...

CVSS3: 9.8
github
больше 3 лет назад

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.

EPSS

Процентиль: 77%
0.01022
Низкий

5.3 Medium

CVSS3