Vulnerability Description
The OpenConnectionTask::handleStateHelper function in Imap/Tasks/OpenConnectionTask.cpp in Trojita before 0.4.1 allows man-in-the-middle attackers to trigger use of cleartext for saving a message into a (1) sent or (2) draft folder via a PREAUTH response that prevents later use of the STARTTLS command.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trojita Project | Trojita | <= 0.4 |
Related Weaknesses (CWE)
References
- http://jkt.flaska.net/blog/Trojita_0_4_1__a_security_update_for_CVE_2014_2567.htVendor Advisory
- https://github.com/jktjkt/trojita/commit/25fffa3e25cbad85bbca804193ad336b090a9ce
- http://jkt.flaska.net/blog/Trojita_0_4_1__a_security_update_for_CVE_2014_2567.htVendor Advisory
- https://github.com/jktjkt/trojita/commit/25fffa3e25cbad85bbca804193ad336b090a9ce
FAQ
What is CVE-2014-2567?
CVE-2014-2567 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The OpenConnectionTask::handleStateHelper function in Imap/Tasks/OpenConnectionTask.cpp in Trojita before 0.4.1 allows man-in-the-middle attackers to trigger use of cleartext for saving a message into...
How severe is CVE-2014-2567?
CVE-2014-2567 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-2567?
Check the references section above for vendor advisories and patch information. Affected products include: Trojita Project Trojita.