Related Vulnerabilities: CVE-2021-38373  

In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.

Severity Medium

Remote Yes

Type Information disclosure

Description

In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.

AVG-2274 kmail 21.04.3-1 Medium Vulnerable

https://bugs.kde.org/show_bug.cgi?id=423423
https://nostarttls.secvuln.info/