MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://gerrit.vesnicky.cesnet.cz/r/1035 | third party advisory patch |
https://bugs.kde.org/show_bug.cgi?id=423453 | issue tracking third party advisory patch |