← Back

CVE-2014-2567

nvd nist
Published: Mar 21, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The OpenConnectionTask::handleStateHelper function in Imap/Tasks/OpenConnectionTask.cpp in Trojita before 0.4.1 allows man-in-the-middle attackers to trigger use of cleartext for saving a message into a (1) sent or (2) draft folder via a PREAUTH response that prevents later use of the STARTTLS command.

Affected (14)

Trojita
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Trojita Project
Up to 0.4
Version 0.1
Version 0.2.9.1
Version 0.2.9.2
Version 0.2.9.3
Version 0.2.9.4
Version 0.2.9
Version 0.2
Version 0.3.90
Version 0.3.91
Version 0.3.92
Version 0.3.93
Version 0.3.96
Version 0.3

Timeline

No history available yet.