CVEs Blog | G5 Cyber Security

CVE-2020-14928 – evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue

evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a “begin TLS” response, eds reads additional data and evaluates it in a TLS context, aka “response injection.”

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14928

Reference (s):

Exit mobile version