imapsync 1.564 and earlier performs a release check by default, which sends sensitive information (imapsync, operating system, and Perl version) to the developer's site.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1000215 | exploit |
http://www.securityfocus.com/bid/65002 | vdb entry |
http://lists.fedoraproject.org/pipermail/package-announce/2014-March/130493.html | vendor advisory |
http://www.mandriva.com/security/advisories?name=MDVSA-2014:060 | vendor advisory |