CVE-2014-2576
Publication date 15 October 2014
Last updated 24 July 2024
Ubuntu priority
Description
plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| claws-mail-extra-plugins | ||
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |