Advisories ยป MGASA-2014-0450

Updated getmail package fixes security vulnerabilities

Publication date: 14 Nov 2014
Modification date: 14 Nov 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-7273 , CVE-2014-7274 , CVE-2014-7275

Description

The IMAP-over-SSL implementation in getmail 4.0.0 through 4.43.0 does not
verify X.509 certificates from SSL servers, which allows man-in-the-middle
attackers to spoof IMAP servers and obtain sensitive information via a crafted
certificate (CVE-2014-7273).

The IMAP-over-SSL implementation in getmail 4.44.0 does not verify that the
server hostname matches a domain name in the subject's Common Name (CN) field
of the X.509 certificate, which allows man-in-the-middle attackers to spoof
IMAP servers and obtain sensitive information via a crafted certificate from
a recognized Certification Authority (CVE-2014-7274).

The POP3-over-SSL implementation in getmail 4.0.0 through 4.44.0 does not
verify X.509 certificates from SSL servers, which allows man-in-the-middle
attackers to spoof POP3 servers and obtain sensitive information via a
crafted certificate (CVE-2014-7275).
                

References

SRPMS

4/core

3/core