cbcvebase.
CVE-2016-10937
published 2019-09-08

CVE-2016-10937: IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.

high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianimapfilter< imapfilter 1:2.6.13-1 (bookworm)imapfilter 1:2.6.13-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
imapfilter_projectimapfilter<= 2.6.12
imapfilter_projectimapfilter>= 0 < 1:2.6.13-11:2.6.13-1
imapfilter_projectimapfilter>= 0 < 1:2.6.13-11:2.6.13-1
imapfilter_projectimapfilter>= 0 < 1:2.6.13-11:2.6.13-1
imapfilter_projectimapfilter>= 0 < 1:2.6.13-11:2.6.13-1
opensusebackports_sle
opensuseleap

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH