CVE-2021-26911

core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:canarymail:canary_mail:3.20:*:*:*:*:iphone_os:*:*
cpe:2.3:a:canarymail:canary_mail:3.21:*:*:*:*:iphone_os:*:*

Configuration 2 (hide)

cpe:2.3:a:libmailcore:mailcore2:0.6.4:*:*:*:*:*:*:*

History

21 Nov 2024, 05:57

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2021/02/17/3 - Mailing List, Patch, Third Party Advisory () http://www.openwall.com/lists/oss-security/2021/02/17/3 - Mailing List, Patch, Third Party Advisory
References () https://apps.apple.com/us/app/canary-mail/id1236045954 - Product, Third Party Advisory () https://apps.apple.com/us/app/canary-mail/id1236045954 - Product, Third Party Advisory
References () https://census-labs.com/news/2021/02/17/canary-mail-app-missing-certificate-validation-check-on-imap-starttls/ - Exploit, Third Party Advisory () https://census-labs.com/news/2021/02/17/canary-mail-app-missing-certificate-validation-check-on-imap-starttls/ - Exploit, Third Party Advisory
References () https://census-labs.com/news/category/advisories/ - Third Party Advisory () https://census-labs.com/news/category/advisories/ - Third Party Advisory
References () https://github.com/canarymail/mailcore2/commit/45acb4efbcaa57a20ac5127dc976538671fce018 - Patch, Third Party Advisory () https://github.com/canarymail/mailcore2/commit/45acb4efbcaa57a20ac5127dc976538671fce018 - Patch, Third Party Advisory
References () https://www.openwall.com/lists/oss-security/2021/02/17/3 - Mailing List, Patch, Third Party Advisory () https://www.openwall.com/lists/oss-security/2021/02/17/3 - Mailing List, Patch, Third Party Advisory

Information

Published : 2021-02-17 21:15

Updated : 2024-11-21 05:57


NVD link : CVE-2021-26911

Mitre link : CVE-2021-26911

CVE.ORG link : CVE-2021-26911


JSON object : View

Products Affected

libmailcore

  • mailcore2

canarymail

  • canary_mail
CWE
CWE-295

Improper Certificate Validation