CVE-2014-2014

imapsync before 1.584, when running with the --tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain credentials by sniffing the network.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gilles_lamiral:imapsync:1.542:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.53:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.525:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.518:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:*:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.569:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.564:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.567:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.554:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.508:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.500:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.547:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.516:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.504:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.558:*:*:*:*:*:*:*

Information

Published : 2014-04-18 15:14

Updated : 2014-04-21 09:19


NVD link : CVE-2014-2014

Mitre link : CVE-2014-2014


JSON object : View

CWE
CWE-255

Credentials Management Errors

Advertisement

dedicated server usa

Products Affected

gilles_lamiral

  • imapsync