Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-10727

Опубликовано: 20 июл. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 9.8

Описание

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.

РелизСтатусПримечание
artful

not-affected

3.26.1-1ubuntu1
bionic

not-affected

3.28.3-0ubuntu0.18.04.1
devel

not-affected

3.28.3-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [3.10.4-0ubuntu1.6]]
esm-infra/bionic

not-affected

3.28.3-0ubuntu0.18.04.1
esm-infra/xenial

released

3.18.5-1ubuntu1.1
precise/esm

DNE

trusty

released

3.10.4-0ubuntu1.6
trusty/esm

DNE

trusty was released [3.10.4-0ubuntu1.6]
upstream

released

3.21.2

Показывать по

EPSS

Процентиль: 77%
0.01022
Низкий

5 Medium

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
больше 9 лет назад

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.

CVSS3: 9.8
nvd
больше 7 лет назад

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.

CVSS3: 9.8
debian
больше 7 лет назад

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in G ...

CVSS3: 9.8
github
больше 3 лет назад

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.

EPSS

Процентиль: 77%
0.01022
Низкий

5 Medium

CVSS2

9.8 Critical

CVSS3