LWN.net Logo

ssmtp: user credentials leak

Package(s):ssmtp CVE #(s):
Created:September 3, 2013 Updated:September 5, 2013
Description: From the Red Hat bugzilla:

It was reported that ssmtp, an extremely simple MTA to get mail off the system to a mail hub, did not perform x509 certificate validation when initiating a TLS connection to server. A rogue server could use this flaw to conduct man-in-the-middle attack, possibly leading to user credentials leak.

Alerts:
Fedora FEDORA-2013-15049 2013-08-30
Fedora FEDORA-2013-15036 2013-08-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds