IMAP Server Response Handling in Alpine Email Client
CVE-2021-38370
5.9MEDIUM
What is CVE-2021-38370?
Prior to version 2.25, the Alpine email client improperly accepts untagged responses from an IMAP server before the STARTTLS command is issued. This lack of secure communication initialization can potentially expose sensitive data to interception during the email retrieval process, emphasizing the importance of proper handling of server responses to ensure user data protection.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
