FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-05-02 10:37:19 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
4a114331-0d24-11e4-8dd2-5453ed2e2b49kdelibs4 -- KMail/KIO POP3 SSL Man-in-the-middle Flaw

Richard J. Moore reports:

The POP3 kioslave used by KMail will accept invalid certificates without presenting a dialog to the user due a bug that leads to an inability to display the dialog combined with an error in the way the result is checked.

This flaw allows an active attacker to perform MITM attacks against the ioslave which could result in the leakage of sensitive data such as the authentication details and the contents of emails.


Discovery 2014-06-17
Entry 2014-07-16
kdelibs
ge 4.10.95 lt 4.12.5_2

CVE-2014-3494
68113
http://lists.kde.org/?l=kde-announce&m=140312275318160&w=2