imapsync before 1.584, when running with the –tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain credentials by sniffing the network.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Imapsync | Imapsync_project | * | 1.580 (including) |
Imapsync | Imapsync_project | 1.53 (including) | 1.53 (including) |
Imapsync | Imapsync_project | 1.500 (including) | 1.500 (including) |
Imapsync | Imapsync_project | 1.504 (including) | 1.504 (including) |
Imapsync | Imapsync_project | 1.508 (including) | 1.508 (including) |
Imapsync | Imapsync_project | 1.516 (including) | 1.516 (including) |
Imapsync | Imapsync_project | 1.518 (including) | 1.518 (including) |
Imapsync | Imapsync_project | 1.525 (including) | 1.525 (including) |
Imapsync | Imapsync_project | 1.542 (including) | 1.542 (including) |
Imapsync | Imapsync_project | 1.547 (including) | 1.547 (including) |
Imapsync | Imapsync_project | 1.554 (including) | 1.554 (including) |
Imapsync | Imapsync_project | 1.558 (including) | 1.558 (including) |
Imapsync | Imapsync_project | 1.564 (including) | 1.564 (including) |
Imapsync | Imapsync_project | 1.567 (including) | 1.567 (including) |
Imapsync | Imapsync_project | 1.569 (including) | 1.569 (including) |
Imapsync | Ubuntu | lucid | * |