CVE Vulnerabilities

CVE-2014-7273

Published: Oct 08, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The IMAP-over-SSL implementation in getmail 4.0.0 through 4.43.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof IMAP servers and obtain sensitive information via a crafted certificate.

Affected Software

NameVendorStart VersionEnd Version
GetmailGetmail4.0 (including)4.0 (including)
GetmailGetmail4.0.0_b10 (including)4.0.0_b10 (including)
GetmailGetmail4.0.1 (including)4.0.1 (including)
GetmailGetmail4.0.2 (including)4.0.2 (including)
GetmailGetmail4.0.3 (including)4.0.3 (including)
GetmailGetmail4.0.4 (including)4.0.4 (including)
GetmailGetmail4.0.5 (including)4.0.5 (including)
GetmailGetmail4.0.6 (including)4.0.6 (including)
GetmailGetmail4.0.7 (including)4.0.7 (including)
GetmailGetmail4.0.8 (including)4.0.8 (including)
GetmailGetmail4.0.9 (including)4.0.9 (including)
GetmailGetmail4.0.10 (including)4.0.10 (including)
GetmailGetmail4.0.11 (including)4.0.11 (including)
GetmailGetmail4.0.12 (including)4.0.12 (including)
GetmailGetmail4.0.13 (including)4.0.13 (including)
GetmailGetmail4.1 (including)4.1 (including)
GetmailGetmail4.1.1 (including)4.1.1 (including)
GetmailGetmail4.1.2 (including)4.1.2 (including)
GetmailGetmail4.1.3 (including)4.1.3 (including)
GetmailGetmail4.1.4 (including)4.1.4 (including)
GetmailGetmail4.1.5 (including)4.1.5 (including)
GetmailGetmail4.2.0 (including)4.2.0 (including)
GetmailGetmail4.3.0 (including)4.3.0 (including)
GetmailGetmail4.4.0 (including)4.4.0 (including)
GetmailGetmail4.5.0 (including)4.5.0 (including)
GetmailGetmail4.6.0 (including)4.6.0 (including)
GetmailGetmail4.7.0 (including)4.7.0 (including)
GetmailGetmail4.8.0 (including)4.8.0 (including)
GetmailGetmail4.9.0 (including)4.9.0 (including)
GetmailGetmail4.10.0 (including)4.10.0 (including)
GetmailGetmail4.11.0 (including)4.11.0 (including)
GetmailGetmail4.12.0 (including)4.12.0 (including)
GetmailGetmail4.13.0 (including)4.13.0 (including)
GetmailGetmail4.14.0 (including)4.14.0 (including)
GetmailGetmail4.15.0 (including)4.15.0 (including)
GetmailGetmail4.16.0 (including)4.16.0 (including)
GetmailGetmail4.17.0 (including)4.17.0 (including)
GetmailGetmail4.18.0 (including)4.18.0 (including)
GetmailGetmail4.19.0 (including)4.19.0 (including)
GetmailGetmail4.20.0 (including)4.20.0 (including)
GetmailGetmail4.21.0 (including)4.21.0 (including)
GetmailGetmail4.22.0 (including)4.22.0 (including)
GetmailGetmail4.23.0 (including)4.23.0 (including)
GetmailGetmail4.24.0 (including)4.24.0 (including)
GetmailGetmail4.25.0 (including)4.25.0 (including)
GetmailGetmail4.26.0 (including)4.26.0 (including)
GetmailGetmail4.27.0 (including)4.27.0 (including)
GetmailGetmail4.28.0 (including)4.28.0 (including)
GetmailGetmail4.29.0 (including)4.29.0 (including)
GetmailGetmail4.30.0 (including)4.30.0 (including)
GetmailGetmail4.31.0 (including)4.31.0 (including)
GetmailGetmail4.32.0 (including)4.32.0 (including)
GetmailGetmail4.33.0 (including)4.33.0 (including)
GetmailGetmail4.34.0 (including)4.34.0 (including)
GetmailGetmail4.35.0 (including)4.35.0 (including)
GetmailGetmail4.36.0 (including)4.36.0 (including)
GetmailGetmail4.37.0 (including)4.37.0 (including)
GetmailGetmail4.38.0 (including)4.38.0 (including)
GetmailGetmail4.39.0 (including)4.39.0 (including)
GetmailGetmail4.40.0 (including)4.40.0 (including)
GetmailGetmail4.41.0 (including)4.41.0 (including)
GetmailGetmail4.42.0 (including)4.42.0 (including)
Getmail4Ubuntulucid*
Getmail4Ubuntuprecise*
Getmail4Ubuntutrusty*
Getmail4Ubuntuupstream*

References