In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked.
References
Link | Resource |
---|---|
https://gitlab.marlam.de/marlam/mpop/commit/b51a6c6b8b83bf0913cc52fa2ff64307e987a5b8 | Patch Third Party Advisory |
https://marlam.de/mpop/news/mpop-1-4-3/ | Patch Third Party Advisory |
https://marlam.de/msmtp/news/ | Patch Vendor Advisory |
https://gitlab.marlam.de/marlam/mpop/commit/b51a6c6b8b83bf0913cc52fa2ff64307e987a5b8 | Patch Third Party Advisory |
https://marlam.de/mpop/news/mpop-1-4-3/ | Patch Third Party Advisory |
https://marlam.de/msmtp/news/ | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:49
Type | Values Removed | Values Added |
---|---|---|
References | () https://gitlab.marlam.de/marlam/mpop/commit/b51a6c6b8b83bf0913cc52fa2ff64307e987a5b8 - Patch, Third Party Advisory | |
References | () https://marlam.de/mpop/news/mpop-1-4-3/ - Patch, Third Party Advisory | |
References | () https://marlam.de/msmtp/news/ - Patch, Vendor Advisory |
Information
Published : 2019-02-13 20:29
Updated : 2024-11-21 04:49
NVD link : CVE-2019-8337
Mitre link : CVE-2019-8337
CVE.ORG link : CVE-2019-8337
JSON object : View
Products Affected
marlam
- msmtp
- mpop
CWE
CWE-295
Improper Certificate Validation