CVE-2007-3209 Information

Description

Mail Notification 4.0 when WITH_SSL is set to 0 at compile time uses unencrypted connections for accounts configured with SSL/TLS which allows remote attackers to obtain sensitive information by sniffing the network.

Reference

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=428157 http://osvdb.org/37205 http://secunia.com/advisories/25600 https://exchange.xforce.ibmcloud.com/vulnerabilities/34814 https://savannah.nongnu.org/bugs/index.php?20131

Share on: