|
|
| |
|
| |
ssmtp: no TLS certificate validation
| Package(s): | ssmtp |
CVE #(s): | |
| Created: | November 1, 2012 |
Updated: | November 7, 2012 |
| Description: |
From the Red Hat bugzilla entry:
It was reported that ssmtp, an extremely simple MTA to get mail off the system to a mail hub, did not perform x509 certificate validation when initiating a TLS connection to server. A rogue server could use this flaw to conduct man-in-the-middle attack, possibly leading to user credentials leak. |
| Alerts: |
|
( Log in to post comments)
|
|
|