Cleartext Message Saving Vulnerability in Trojita

Cleartext Message Saving Vulnerability in Trojita

CVE-2014-2567 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

The OpenConnectionTask::handleStateHelper function in Imap/Tasks/OpenConnectionTask.cpp in Trojita before 0.4.1 allows man-in-the-middle attackers to trigger use of cleartext for saving a message into a (1) sent or (2) draft folder via a PREAUTH response that prevents later use of the STARTTLS command.

Learn more about our Web Application Penetration Testing UK.