|
|
| |
|
| |
isync: information disclosure
| Package(s): | isync |
CVE #(s): | CVE-2013-0289
|
| Created: | March 4, 2013 |
Updated: | March 6, 2013 |
| Description: |
From the Red Hat bugzilla:
A security flaw was found in the way isync, a command line application to synchronize IMAP4 and Maildir mailboxes, (previously) performed server's SSL x509.v3 certificate validation, when performing IMAP protocol based synchronization (server's hostname was previously not compared for match the CN field of the certificate). A rogue server could use this flaw to conduct man-in-the-middle (MiTM) attacks, possibly leading to disclosure of sensitive information. |
| Alerts: |
|
( Log in to post comments)
|
|
|