5.8
CVSSv2

CVE-2014-7274

Published: 08/10/2014 Updated: 22/12/2014
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

The IMAP-over-SSL implementation in getmail 4.44.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof IMAP servers and obtain sensitive information via a crafted certificate from a recognized Certification Authority.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

getmail getmail 4.44.0

Vendor Advisories

Debian Bug report logs - #766670 getmail4: unpatched security issues (MITM) in stable Package: getmail4; Maintainer for getmail4 is Osamu Aoki <osamu@debianorg>; Source for getmail4 is src:getmail (PTS, buildd, popcon) Reported by: Henrique de Moraes Holschuh <hmh@debianorg> Date: Fri, 24 Oct 2014 18:06:01 UTC Sev ...