Your submission was sent successfully! Close

CVE-2011-3355

Published: 25 November 2019

evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could use this flaw to obtain login credentials of the victim.

Priority

Medium

CVSS 3 base score: 7.3

Status

Package Release Status
evolution-data-server
Launchpad, Ubuntu, Debian
Upstream
Released (3.1.2)
Patches:
Upstream: http://git.gnome.org/browse/evolution-data-server/commit/?id=e0ac4d79705c