CVE-2014-2014

imapsync before 1.584, when running with the --tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain credentials by sniffing the network.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:imapsync_project:imapsync:*:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.53:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.500:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.504:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.508:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.516:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.518:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.525:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.542:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.547:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.554:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.558:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.564:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.567:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.569:*:*:*:*:*:*:*

History

21 Nov 2024, 02:05

Type Values Removed Values Added
References () http://seclists.org/oss-sec/2014/q1/367 - () http://seclists.org/oss-sec/2014/q1/367 -
References () http://seclists.org/oss-sec/2014/q1/378 - Patch () http://seclists.org/oss-sec/2014/q1/378 - Patch
References () http://www.linux-france.org/prj/imapsync_list/msg01907.html - () http://www.linux-france.org/prj/imapsync_list/msg01907.html -
References () http://www.linux-france.org/prj/imapsync_list/msg01910.html - () http://www.linux-france.org/prj/imapsync_list/msg01910.html -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2014:060 - () http://www.mandriva.com/security/advisories?name=MDVSA-2014:060 -
References () https://bugs.mageia.org/show_bug.cgi?id=12770 - () https://bugs.mageia.org/show_bug.cgi?id=12770 -
References () https://github.com/imapsync/imapsync/issues/15 - () https://github.com/imapsync/imapsync/issues/15 -
References () https://lists.fedoraproject.org/pipermail/package-announce/2014-February/128293.html - () https://lists.fedoraproject.org/pipermail/package-announce/2014-February/128293.html -

07 Jun 2023, 13:59

Type Values Removed Values Added
First Time Imapsync Project
Imapsync Project imapsync
CPE cpe:2.3:a:gilles_lamiral:imapsync:1.564:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.525:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.516:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.500:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.53:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.518:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.508:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.504:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.542:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.567:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.569:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.554:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.558:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:*:*:*:*:*:*:*:*
cpe:2.3:a:gilles_lamiral:imapsync:1.547:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.508:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.518:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.504:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.569:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.554:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.564:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:*:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.500:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.547:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.525:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.53:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.558:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.567:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.542:*:*:*:*:*:*:*
cpe:2.3:a:imapsync_project:imapsync:1.516:*:*:*:*:*:*:*

Information

Published : 2014-04-18 22:14

Updated : 2024-11-21 02:05


NVD link : CVE-2014-2014

Mitre link : CVE-2014-2014

CVE.ORG link : CVE-2014-2014


JSON object : View

Products Affected

imapsync_project

  • imapsync
CWE
CWE-255

Credentials Management Errors