In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked.
References
Link | Resource |
---|---|
https://marlam.de/msmtp/news/ | Patch Vendor Advisory |
https://marlam.de/mpop/news/mpop-1-4-3/ | Patch Third Party Advisory |
https://gitlab.marlam.de/marlam/mpop/commit/b51a6c6b8b83bf0913cc52fa2ff64307e987a5b8 | Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-02-13 12:29
Updated : 2019-03-01 08:39
NVD link : CVE-2019-8337
Mitre link : CVE-2019-8337
JSON object : View
CWE
CWE-295
Improper Certificate Validation
Products Affected
marlam
- msmtp
- mpop