[Git][security-tracker-team/security-tracker][master] Add new set of STARTTLS issues to be checked in more detail

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 10 21:30:20 BST 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7c961678 by Salvatore Bonaccorso at 2021-08-10T22:29:51+02:00
Add new set of STARTTLS issues to be checked in more detail

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -27,13 +27,20 @@ CVE-2021-38375
 CVE-2021-38374
 	RESERVED
 CVE-2021-38373 (In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not hon ...)
-	TODO: check
+	- kmail <unfixed>
+	NOTE: https://bugs.kde.org/show_bug.cgi?id=423423
+	NOTE: https://nostarttls.secvuln.info
+	TODO: check details
 CVE-2021-38372 (In KDE Trojita 0.7, man-in-the-middle attackers can create new folders ...)
 	TODO: check
 CVE-2021-38371 (The STARTTLS feature in Exim through 4.94.2 allows response injection  ...)
-	TODO: check
+	- exim4 <unfixed>
+	NOTE: https://nostarttls.secvuln.info
+	NOTE: https://www.exim.org/static/doc/security/CVE-2021-38371.txt
 CVE-2021-38370 (In Alpine through 2.24, untagged responses from an IMAP server are acc ...)
-	TODO: check
+	- alpine <unfixed>
+	NOTE: https://nostarttls.secvuln.info
+	TODO: check details
 CVE-2021-38369
 	RESERVED
 CVE-2021-38368



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7c961678f5ed70f0786f622eb206c2874e03fd34

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7c961678f5ed70f0786f622eb206c2874e03fd34
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210810/8cbaa73f/attachment.htm>


More information about the debian-security-tracker-commits mailing list