Mail Notification 4.0, when WITH_SSL is set to 0 at compile time, uses unencrypted connections for accounts configured with SSL/TLS, which allows remote attackers to obtain sensitive information by sniffing the network.
Link | Tags |
---|---|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=428157 | |
http://secunia.com/advisories/25600 | third party advisory vendor advisory |
http://osvdb.org/37205 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34814 | vdb entry |
https://savannah.nongnu.org/bugs/index.php?20131 |