Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <53015783.8030100@redhat.com>
Date: Mon, 17 Feb 2014 11:27:47 +1100
From: Murray McAllister <mmcallis@...hat.com>
To: oss-security@...ts.openwall.com
Subject: CVE request: "imapsync ignores the --tls switch and sends my authentication
 plaintext."

Hello,

https://bugs.mageia.org/show_bug.cgi?id=12770 notes that imapsync 1.584 
fixes a security issue, "Bug fix: Check if going to tls is ok, exit 
otherwise with explicit error message. Thanks to Dennis Schridde for 
reporting this ugly bug that deserves a CVE."

Upstream bug: https://github.com/imapsync/imapsync/issues/15

Can a CVE please be assigned if one has not been already?

Thanks,

--
Murray McAllister / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.