CVE-2020-14928 — Injection in Evolution-data-server
Severity
5.9MEDIUMNVD
EPSS
6.4%
top 8.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 17
Latest updateMay 24
Description
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6
Affected Packages2 packages
Also affects: Debian Linux 10.0, 9.0, Fedora 31, Ubuntu Linux 16.04, 18.04, 20.04