7.8
CVSSv2

CVE-2007-3209

Published: 14/06/2007 Updated: 29/07/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Mail Notification 4.0, when WITH_SSL is set to 0 at compile time, uses unencrypted connections for accounts configured with SSL/TLS, which allows remote malicious users to obtain sensitive information by sniffing the network.

Vulnerable Product Search on Vulmon Subscribe to Product

nongnu mail notification 4.0

Vendor Advisories

Debian Bug report logs - #428157 [CVE-2007-3209] Silently falls back to unencrypted connection: password sent in cleartext Package: mail-notification; Maintainer for mail-notification is Stephen Kitt <skitt@debianorg>; Source for mail-notification is src:mail-notification (PTS, buildd, popcon) Reported by: Ted Percival < ...