IMAP Server Response Handling in Alpine Email Client
CVE-2021-38370
5.9MEDIUM
What is CVE-2021-38370?
Prior to version 2.25, the Alpine email client improperly accepts untagged responses from an IMAP server before the STARTTLS command is issued. This lack of secure communication initialization can potentially expose sensitive data to interception during the email retrieval process, emphasizing the importance of proper handling of server responses to ensure user data protection.