4.3
CVSSv2

CVE-2021-38370

Published: 10/08/2021 Updated: 13/01/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

In Alpine prior to 2.25, untagged responses from an IMAP server are accepted before STARTTLS.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

alpine project alpine

Vendor Advisories

Debian Bug report logs - #992171 alpine: CVE-2021-38370 Package: src:alpine; Maintainer for src:alpine is Asheesh Laroia <asheesh@asheeshorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Aug 2021 20:24:02 UTC Severity: important Tags: security, upstream Found in versions alpine/224+dfsg1-1, ...