CVE-2014-2576 — Claws-mail vulnerability
Severity
6.8MEDIUMNVD
EPSS
0.7%
top 28.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 15
Latest updateMay 14
Description
plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
CVSS vector
AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4
Affected Packages3 packages
🔴Vulnerability Details
3📋Vendor Advisories
1Debian▶
CVE-2014-2576: claws-mail - plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFY...↗2014
💬Community
3Bugzilla▶
CVE-2014-2576 claws-mail: RSSyl plug-in does not verify SSL certificates allowing man-in-the-middle attacks [fedora-all]↗2014-03-27
Bugzilla▶
CVE-2014-2576 claws-mail: RSSyl plug-in does not verify SSL certificates allowing man-in-the-middle attacks↗2014-03-27
Bugzilla▶
CVE-2014-2576 claws-mail: RSSyl plug-in does not verify SSL certificates allowing man-in-the-middle attacks [epel-all]↗2014-03-27