The camel component for Ximian Evolution 1.0.x and earlier does not verify certificates when it establishes a new SSL connection after previously verifying a certificate, which could allow remote attackers to monitor or modify sessions via a man-in-the-middle attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Evolution | Ximian | 1.0.3 (including) | 1.0.3 (including) |
Evolution | Ximian | 1.0.4 (including) | 1.0.4 (including) |
Evolution | Ximian | 1.0.5 (including) | 1.0.5 (including) |
Evolution | Ximian | 1.0.6 (including) | 1.0.6 (including) |
Evolution | Ximian | 1.0.7 (including) | 1.0.7 (including) |
Evolution | Ximian | 1.0.8 (including) | 1.0.8 (including) |