Geary before 0.6.3 does not present the user with a warning when a TLS certificate error is detected, which makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Geary | Yorba | * | 0.5.0 (including) |
Geary | Ubuntu | trusty | * |
Geary | Ubuntu | upstream | * |