LWN.net Logo

isync: information disclosure

Package(s):isync CVE #(s):CVE-2013-0289
Created:March 4, 2013 Updated:March 6, 2013
Description: From the Red Hat bugzilla:

A security flaw was found in the way isync, a command line application to synchronize IMAP4 and Maildir mailboxes, (previously) performed server's SSL x509.v3 certificate validation, when performing IMAP protocol based synchronization (server's hostname was previously not compared for match the CN field of the certificate). A rogue server could use this flaw to conduct man-in-the-middle (MiTM) attacks, possibly leading to disclosure of sensitive information.

Alerts:
Fedora FEDORA-2013-2795 2013-03-03
Fedora FEDORA-2013-2758 2013-03-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds