CVE-2013-4584
published 2019-11-15CVE-2013-4584: Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers…
PriorityP427medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
1.52%
72.1th percentile
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | perdition | < perdition 2.1-1 (bookworm) | perdition 2.1-1 (bookworm) |
| horms | perdition | < 2.1 | 2.1 |
| perdition | perdition | — | — |
| perdition | perdition | >= 0 < 2.1-1 | 2.1-1 |
| perdition | perdition | >= 0 < 2.1-1 | 2.1-1 |
| perdition | perdition | >= 0 < 2.1-1 | 2.1-1 |
| perdition | perdition | >= 0 < 2.1-1 | 2.1-1 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_debian5.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6rm7-87pc-2jw9: Perdition before 2
ghsa_unreviewed·2022-05-05
CVE-2013-4584 [MEDIUM] CWE-755 GHSA-6rm7-87pc-2jw9: Perdition before 2
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections
OSV
CVE-2013-4584: Perdition before 2
osv·2019-11-15·CVSS 5.9
CVE-2013-4584 [MEDIUM] CVE-2013-4584: Perdition before 2
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections
Debian
CVE-2013-4584: perdition - Perdition before 2.2 may have weak security when handling outbound connections, ...
vendor_debian·2013·CVSS 5.9
CVE-2013-4584 [MEDIUM] CVE-2013-4584: perdition - Perdition before 2.2 may have weak security when handling outbound connections, ...
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections
Scope: local
bookworm: resolved (fixed in 2.1-1)
bullseye: resolved (fixed in 2.1-1)
forky: resolved (fixed in 2.1-1)
sid: resolved (fixed in 2.1-1)
trixie: resolved (fixed in 2.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2013/11/15/6http://www.securityfocus.com/bid/63696https://access.redhat.com/security/cve/cve-2013-4584https://exchange.xforce.ibmcloud.com/vulnerabilities/89184https://github.com/horms/perdition/commit/62a0ce94aeb7dd99155882956ce9e327ab914ddfhttps://security-tracker.debian.org/tracker/CVE-2013-4584http://www.openwall.com/lists/oss-security/2013/11/15/6http://www.securityfocus.com/bid/63696https://access.redhat.com/security/cve/cve-2013-4584https://exchange.xforce.ibmcloud.com/vulnerabilities/89184https://github.com/horms/perdition/commit/62a0ce94aeb7dd99155882956ce9e327ab914ddfhttps://security-tracker.debian.org/tracker/CVE-2013-4584
2019-11-15
Published