CVE-2011-3355 Information

Description

evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder when the Sent folder was located on the remote server. An attacker could use this flaw to obtain login credentials of the victim.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Reference

https://access.redhat.com/security/cve/cve-2011-3355 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=641052 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3355 https://security-tracker.debian.org/tracker/CVE-2011-3355 https://www.openwall.com/lists/oss-security/2011/09/09/1

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

LOW

Base Severity

7.3

Share on: