CVE Vulnerabilities

CVE-2014-2014

Published: Apr 18, 2014 | Modified: Jun 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

imapsync before 1.584, when running with the –tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain credentials by sniffing the network.

Affected Software

Name Vendor Start Version End Version
Imapsync Imapsync_project * 1.580 (including)
Imapsync Imapsync_project 1.53 (including) 1.53 (including)
Imapsync Imapsync_project 1.500 (including) 1.500 (including)
Imapsync Imapsync_project 1.504 (including) 1.504 (including)
Imapsync Imapsync_project 1.508 (including) 1.508 (including)
Imapsync Imapsync_project 1.516 (including) 1.516 (including)
Imapsync Imapsync_project 1.518 (including) 1.518 (including)
Imapsync Imapsync_project 1.525 (including) 1.525 (including)
Imapsync Imapsync_project 1.542 (including) 1.542 (including)
Imapsync Imapsync_project 1.547 (including) 1.547 (including)
Imapsync Imapsync_project 1.554 (including) 1.554 (including)
Imapsync Imapsync_project 1.558 (including) 1.558 (including)
Imapsync Imapsync_project 1.564 (including) 1.564 (including)
Imapsync Imapsync_project 1.567 (including) 1.567 (including)
Imapsync Imapsync_project 1.569 (including) 1.569 (including)
Imapsync Ubuntu lucid *

References