Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2005-3402

Опубликовано: 01 нояб. 2005
Источник: ubuntu
Приоритет: medium
CVSS2: 2.6

Описание

The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to obtain authentication information without detection via a man-in-the-middle (MITM) attack that bypasses TLS authentication or downgrades CRAM-MD5 authentication to plain authentication.

РелизСтатусПримечание
dapper

ignored

end of life
devel

ignored

negligible
edgy

ignored

end of life
feisty

ignored

end of life
upstream

needs-triage

Показывать по

Ссылки на источники

2.6 Low

CVSS2

Связанные уязвимости

nvd
больше 20 лет назад

The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to obtain authentication information without detection via a man-in-the-middle (MITM) attack that bypasses TLS authentication or downgrades CRAM-MD5 authentication to plain authentication.

debian
больше 20 лет назад

The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly ...

github
почти 4 года назад

The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to obtain authentication information without detection via a man-in-the-middle (MITM) attack that bypasses TLS authentication or downgrades CRAM-MD5 authentication to plain authentication.

2.6 Low

CVSS2