Vulnerability Description
In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Marlam | Mpop | 1.4.2 |
| Marlam | Msmtp | 1.8.2 |
Related Weaknesses (CWE)
References
- https://gitlab.marlam.de/marlam/mpop/commit/b51a6c6b8b83bf0913cc52fa2ff64307e987PatchThird Party Advisory
- https://marlam.de/mpop/news/mpop-1-4-3/PatchThird Party Advisory
- https://marlam.de/msmtp/news/PatchVendor Advisory
- https://gitlab.marlam.de/marlam/mpop/commit/b51a6c6b8b83bf0913cc52fa2ff64307e987PatchThird Party Advisory
- https://marlam.de/mpop/news/mpop-1-4-3/PatchThird Party Advisory
- https://marlam.de/msmtp/news/PatchVendor Advisory
FAQ
What is CVE-2019-8337?
CVE-2019-8337 is a vulnerability with a CVSS score of 5.3 (MEDIUM). In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked.
How severe is CVE-2019-8337?
CVE-2019-8337 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-8337?
Check the references section above for vendor advisories and patch information. Affected products include: Marlam Mpop, Marlam Msmtp.