CVE Vulnerabilities

CVE-2014-2014

Published: Apr 18, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

imapsync before 1.584, when running with the –tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain credentials by sniffing the network.

Affected Software

NameVendorStart VersionEnd Version
ImapsyncImapsync_project*1.580 (including)
ImapsyncImapsync_project1.53 (including)1.53 (including)
ImapsyncImapsync_project1.500 (including)1.500 (including)
ImapsyncImapsync_project1.504 (including)1.504 (including)
ImapsyncImapsync_project1.508 (including)1.508 (including)
ImapsyncImapsync_project1.516 (including)1.516 (including)
ImapsyncImapsync_project1.518 (including)1.518 (including)
ImapsyncImapsync_project1.525 (including)1.525 (including)
ImapsyncImapsync_project1.542 (including)1.542 (including)
ImapsyncImapsync_project1.547 (including)1.547 (including)
ImapsyncImapsync_project1.554 (including)1.554 (including)
ImapsyncImapsync_project1.558 (including)1.558 (including)
ImapsyncImapsync_project1.564 (including)1.564 (including)
ImapsyncImapsync_project1.567 (including)1.567 (including)
ImapsyncImapsync_project1.569 (including)1.569 (including)
ImapsyncUbuntulucid*

References