NA

CVE-2024-34083

Published: 18/05/2024 Updated: 20/05/2024

Vulnerability Summary

aiosmptd is a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted connection. This could be exploited by a man-in-the-middle attack. Version 1.4.6 contains a patch for the issue.

Vendor Advisories

Debian Bug report logs - #1072119 python-aiosmtpd: CVE-2024-34083 Package: src:python-aiosmtpd; Maintainer for src:python-aiosmtpd is Debian Python Team <team+python@trackerdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Tue, 28 May 2024 20:42:04 UTC Severity: grave Tags: security, upstream ...