STARTTLS Buffering Issue in Evolution Data Server by GNOME
CVE-2020-14928
5.9MEDIUM
What is CVE-2020-14928?
The evolution-data-server prior to version 3.36.3 is susceptible to a STARTTLS buffering vulnerability that occurs during the handling of SMTP and POP3 protocols. When a server issues a 'begin TLS' response, the server improperly processes subsequent data as TLS data, leading to potential response injection risks. This flaw can allow attackers to exploit the vulnerability to manipulate communication, potentially intercepting sensitive information.
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved