CVE-2014-2576Claws-mail vulnerability

CWE-3108 documents6 sources
Severity
6.8MEDIUMNVD
EPSS
0.7%
top 28.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 15
Latest updateMay 14

Description

plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

Debianclaws-mail/claws-mail< 3.10.1-1+3
NVDopensuse/opensuse12.3, 13.1+1

🔴Vulnerability Details

3
GHSA
GHSA-fc99-wqm7-mj5r: plugins/rssyl/feed2022-05-14
OSV
CVE-2014-2576: plugins/rssyl/feed2014-10-15
CVEList
CVE-2014-2576: plugins/rssyl/feed2014-10-15

📋Vendor Advisories

1
Debian
CVE-2014-2576: claws-mail - plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFY...2014

💬Community

3
Bugzilla
CVE-2014-2576 claws-mail: RSSyl plug-in does not verify SSL certificates allowing man-in-the-middle attacks [fedora-all]2014-03-27
Bugzilla
CVE-2014-2576 claws-mail: RSSyl plug-in does not verify SSL certificates allowing man-in-the-middle attacks2014-03-27
Bugzilla
CVE-2014-2576 claws-mail: RSSyl plug-in does not verify SSL certificates allowing man-in-the-middle attacks [epel-all]2014-03-27
CVE-2014-2576 — Claws-mail vulnerability | cvebase