STARTTLS Buffering Issue in Evolution Data Server by GNOME
CVE-2020-14928
5.9MEDIUM
What is CVE-2020-14928?
The evolution-data-server prior to version 3.36.3 is susceptible to a STARTTLS buffering vulnerability that occurs during the handling of SMTP and POP3 protocols. When a server issues a 'begin TLS' response, the server improperly processes subsequent data as TLS data, leading to potential response injection risks. This flaw can allow attackers to exploit the vulnerability to manipulate communication, potentially intercepting sensitive information.