offlineimap before 6.3.2 does not check for SSL server certificate validation when ssl = yes option is specified which can allow man-in-the-middle attacks.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Debian_linux | Debian | 8.0 (including) | 8.0 (including) |
Debian_linux | Debian | 9.0 (including) | 9.0 (including) |
Debian_linux | Debian | 10.0 (including) | 10.0 (including) |
Offlineimap | Ubuntu | hardy | * |
Offlineimap | Ubuntu | lucid | * |
Offlineimap | Ubuntu | maverick | * |
Offlineimap | Ubuntu | natty | * |
Offlineimap | Ubuntu | oneiric | * |
Offlineimap | Ubuntu | quantal | * |
Offlineimap | Ubuntu | raring | * |
Offlineimap | Ubuntu | saucy | * |
Offlineimap | Ubuntu | upstream | * |