Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-2576
Description:plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man- in-the-middle (MITM) attacks.
Test IDs: 1.3.6.1.4.1.25623.1.1.10.2014.0449  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-2576
http://sourceforge.net/p/claws-mail/news/2014/05/claws-mail-3100-unleashed/
http://seclists.org/oss-sec/2014/q1/636
http://secunia.com/advisories/60422
SuSE Security Announcement: openSUSE-SU-2014:1291 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-10/msg00015.html




© 1998-2025 E-Soft Inc. All rights reserved.