KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://bugs.kde.org/show_bug.cgi?id=423426 | vendor advisory |
https://lists.debian.org/debian-lts-announce/2020/07/msg00030.html | third party advisory mailing list |