LWN.net Logo

ssmtp: no TLS certificate validation

Package(s):ssmtp CVE #(s):
Created:November 1, 2012 Updated:November 7, 2012
Description:

From the Red Hat bugzilla entry:

It was reported that ssmtp, an extremely simple MTA to get mail off the system to a mail hub, did not perform x509 certificate validation when initiating a TLS connection to server. A rogue server could use this flaw to conduct man-in-the-middle attack, possibly leading to user credentials leak.

Alerts:
Fedora FEDORA-2012-16163 2012-11-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds