Source: offlineimap3
Version: 8.0.2+dfsg-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/OfflineIMAP/offlineimap3/issues/222 
https://github.com/OfflineIMAP/offlineimap/issues/669
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for offlineimap3.

CVE-2020-37248[0]:
| OfflineIMAP before 8.0.3 trusts the server with their STARTTLS
| capability prior to authentication, which allows STRIPTLS/man-in-
| the-middle attacks, taking over the connection and extracting
| account credentials in cleartext.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2020-37248
    https://www.cve.org/CVERecord?id=CVE-2020-37248
[1] https://github.com/OfflineIMAP/offlineimap3/issues/222
[2] https://github.com/OfflineIMAP/offlineimap/issues/669 
[3] 
https://github.com/OfflineIMAP/offlineimap3/commit/46505c53ef995455d66c685f9ec3ff6ea93dbb74

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to