CVE-2014-2014
Publication date 18 April 2014
Last updated 24 July 2024
Ubuntu priority
Description
imapsync before 1.584, when running with the --tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain credentials by sniffing the network.