CVE-2014-2576
published 2014-10-15CVE-2014-2576: plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote…
PriorityP428medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.00%
78.5th percentile
plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| claws-mail | claws-mail | <= 3.9.3 | — |
| claws-mail | claws-mail | >= 0 < 3.10.1-1 | 3.10.1-1 |
| claws-mail | claws-mail | >= 0 < 3.10.1-1 | 3.10.1-1 |
| claws-mail | claws-mail | >= 0 < 3.10.1-1 | 3.10.1-1 |
| claws-mail | claws-mail | >= 0 < 3.10.1-1 | 3.10.1-1 |
| debian | claws-mail | < claws-mail 3.10.1-1 (bookworm) | claws-mail 3.10.1-1 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fc99-wqm7-mj5r: plugins/rssyl/feed
ghsa_unreviewed·2022-05-14
CVE-2014-2576 [MEDIUM] GHSA-fc99-wqm7-mj5r: plugins/rssyl/feed
plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
OSV
CVE-2014-2576: plugins/rssyl/feed
osv·2014-10-15·CVSS 6.8
CVE-2014-2576 [MEDIUM] CVE-2014-2576: plugins/rssyl/feed
plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
Debian
CVE-2014-2576: claws-mail - plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFY...
vendor_debian·2014·CVSS 6.8
CVE-2014-2576 [MEDIUM] CVE-2014-2576: claws-mail - plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFY...
plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
Scope: local
bookworm: resolved (fixed in 3.10.1-1)
bullseye: resolved (fixed in 3.10.1-1)
forky: resolved (fixed in 3.10.1-1)
sid: resolved (fixed in 3.10.1-1)
trixie: resolved (fixed in 3.10.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-2576 claws-mail: RSSyl plug-in does not verify SSL certificates allowing man-in-the-middle attacks [fedora-all]
bugzilla·2014-03-27·CVSS 6.8
CVE-2014-2576 [MEDIUM] CVE-2014-2576 claws-mail: RSSyl plug-in does not verify SSL certificates allowing man-in-the-middle attacks [fedora-all]
CVE-2014-2576 claws-mail: RSSyl plug-in does not verify SSL certificates allowing man-in-the-middle attacks [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field w
Bugzilla
CVE-2014-2576 claws-mail: RSSyl plug-in does not verify SSL certificates allowing man-in-the-middle attacks
bugzilla·2014-03-27·CVSS 6.8
CVE-2014-2576 [MEDIUM] CVE-2014-2576 claws-mail: RSSyl plug-in does not verify SSL certificates allowing man-in-the-middle attacks
CVE-2014-2576 claws-mail: RSSyl plug-in does not verify SSL certificates allowing man-in-the-middle attacks
Marcus Meissner reported that the Claws Mail's RSSyl plug-in, an RSS feed aggregator, does not verify SSL certificates:
http://www.thewildbeast.co.uk/claws-mail/bugzilla/show_bug.cgi?id=3106
This allows for man-in-the-middle attacks. This issue was assigned CVE-2014-2576:
http://seclists.org/oss-sec/2014/q1/636
Discussion:
Created claws-mail tracking bugs for this issue:
Affects: fedora-all [bug 1081358]
Affects: epel-all [bug 1081359]
---
ARRAY(0x558ebdcb1710)
Bugzilla
CVE-2014-2576 claws-mail: RSSyl plug-in does not verify SSL certificates allowing man-in-the-middle attacks [epel-all]
bugzilla·2014-03-27·CVSS 6.8
CVE-2014-2576 [MEDIUM] CVE-2014-2576 claws-mail: RSSyl plug-in does not verify SSL certificates allowing man-in-the-middle attacks [epel-all]
CVE-2014-2576 claws-mail: RSSyl plug-in does not verify SSL certificates allowing man-in-the-middle attacks [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes fiel
http://lists.opensuse.org/opensuse-updates/2014-10/msg00015.htmlhttp://seclists.org/oss-sec/2014/q1/636http://secunia.com/advisories/60422http://sourceforge.net/p/claws-mail/news/2014/05/claws-mail-3100-unleashed/http://www.thewildbeast.co.uk/claws-mail/bugzilla/show_bug.cgi?id=3106http://lists.opensuse.org/opensuse-updates/2014-10/msg00015.htmlhttp://seclists.org/oss-sec/2014/q1/636http://secunia.com/advisories/60422http://sourceforge.net/p/claws-mail/news/2014/05/claws-mail-3100-unleashed/http://www.thewildbeast.co.uk/claws-mail/bugzilla/show_bug.cgi?id=3106
2014-10-15
Published