CVE-2011-3355

evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could use this flaw to obtain login credentials of the victim.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:gnome:evolution-data-server3:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

21 Nov 2024, 01:30

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/cve-2011-3355 - Third Party Advisory () https://access.redhat.com/security/cve/cve-2011-3355 - Third Party Advisory
References () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=641052 - Third Party Advisory () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=641052 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3355 - Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3355 - Issue Tracking, Third Party Advisory
References () https://security-tracker.debian.org/tracker/CVE-2011-3355 - Third Party Advisory () https://security-tracker.debian.org/tracker/CVE-2011-3355 - Third Party Advisory
References () https://www.openwall.com/lists/oss-security/2011/09/09/1 - Exploit, Mailing List () https://www.openwall.com/lists/oss-security/2011/09/09/1 - Exploit, Mailing List

Information

Published : 2019-11-25 23:15

Updated : 2024-11-21 01:30


NVD link : CVE-2011-3355

Mitre link : CVE-2011-3355

CVE.ORG link : CVE-2011-3355


JSON object : View

Products Affected

linux

  • linux_kernel

gnome

  • evolution-data-server3
CWE
CWE-311

Missing Encryption of Sensitive Data