IMAP Server Vulnerability: Accepting Untagged Responses Before STARTTLS in Alpine

IMAP Server Vulnerability: Accepting Untagged Responses Before STARTTLS in Alpine

CVE-2021-38370 · MEDIUM Severity

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.

Learn more about our Cis Benchmark Audit For Server Software.