7.4
CVSSv3

CVE-2020-15953

Published: 27/07/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.4 | Impact Score: 5.2 | Exploitability Score: 2.2
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

LibEtPan up to and including 1.9.4, as used in MailCore 2 up to and including 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a meddler-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libetpan project libetpan

libmailcore mailcore2

fedoraproject fedora 31

fedoraproject fedora 32

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #966647 libetpan: CVE-2020-15953 Package: src:libetpan; Maintainer for src:libetpan is Ricardo Mones <mones@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 1 Aug 2020 06:15:02 UTC Severity: important Tags: security, upstream Found in version libetpan/194-2 ...
LibEtPan 194 has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3 When a server sends a "begin TLS" response, the client reads additional data (eg, from a meddler-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection" ...