In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. This allows e-mail messages and user credentials to be sent to the MitM attacker.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15955
Reference (s):
- https://nostarttls.secvuln.info/
- https://www.fehcom.de/sqmail/sqmail.html

