The POP3-over-SSL implementation in getmail 4.0.0 through 4.44.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof POP3 servers and obtain sensitive information via a crafted certificate.
2014-10-08T01:55:05.830
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | getmail | getmail | 4.0.1 | Yes |
Application | getmail | getmail | 4.0.2 | Yes |
Application | getmail | getmail | 4.0.3 | Yes |
Application | getmail | getmail | 4.0.4 | Yes |
Application | getmail | getmail | 4.0.5 | Yes |
Application | getmail | getmail | 4.0.6 | Yes |
Application | getmail | getmail | 4.0.7 | Yes |
Application | getmail | getmail | 4.0.8 | Yes |
Application | getmail | getmail | 4.0.9 | Yes |
Application | getmail | getmail | 4.0.10 | Yes |
Application | getmail | getmail | 4.0.11 | Yes |
Application | getmail | getmail | 4.0.12 | Yes |
Application | getmail | getmail | 4.0.13 | Yes |
Application | getmail | getmail | 4.1 | Yes |
Application | getmail | getmail | 4.1.1 | Yes |
Application | getmail | getmail | 4.1.2 | Yes |
Application | getmail | getmail | 4.1.3 | Yes |
Application | getmail | getmail | 4.1.4 | Yes |
Application | getmail | getmail | 4.1.5 | Yes |
Application | getmail | getmail | 4.2.0 | Yes |
Application | getmail | getmail | 4.3.0 | Yes |
Application | getmail | getmail | 4.4.0 | Yes |
Application | getmail | getmail | 4.5.0 | Yes |
Application | getmail | getmail | 4.6.0 | Yes |
Application | getmail | getmail | 4.7.0 | Yes |
Application | getmail | getmail | 4.8.0 | Yes |
Application | getmail | getmail | 4.9.0 | Yes |
Application | getmail | getmail | 4.10.0 | Yes |
Application | getmail | getmail | 4.11.0 | Yes |
Application | getmail | getmail | 4.12.0 | Yes |
Application | getmail | getmail | 4.13.0 | Yes |
Application | getmail | getmail | 4.14.0 | Yes |
Application | getmail | getmail | 4.15.0 | Yes |
Application | getmail | getmail | 4.16.0 | Yes |
Application | getmail | getmail | 4.17.0 | Yes |
Application | getmail | getmail | 4.18.0 | Yes |
Application | getmail | getmail | 4.19.0 | Yes |
Application | getmail | getmail | 4.20.0 | Yes |
Application | getmail | getmail | 4.21.0 | Yes |
Application | getmail | getmail | 4.22.0 | Yes |
Application | getmail | getmail | 4.23.0 | Yes |
Application | getmail | getmail | 4.24.0 | Yes |
Application | getmail | getmail | 4.25.0 | Yes |
Application | getmail | getmail | 4.26.0 | Yes |
Application | getmail | getmail | 4.27.0 | Yes |
Application | getmail | getmail | 4.28.0 | Yes |
Application | getmail | getmail | 4.29.0 | Yes |
Application | getmail | getmail | 4.30.0 | Yes |
Application | getmail | getmail | 4.31.0 | Yes |
Application | getmail | getmail | 4.32.0 | Yes |
Application | getmail | getmail | 4.33.0 | Yes |
Application | getmail | getmail | 4.34.0 | Yes |
Application | getmail | getmail | 4.35.0 | Yes |
Application | getmail | getmail | 4.36.0 | Yes |
Application | getmail | getmail | 4.37.0 | Yes |
Application | getmail | getmail | 4.38.0 | Yes |
Application | getmail | getmail | 4.39.0 | Yes |
Application | getmail | getmail | 4.40.0 | Yes |
Application | getmail | getmail | 4.41.0 | Yes |
Application | getmail | getmail | 4.42.0 | Yes |
Application | getmail | getmail | 4.43.0 | Yes |
Application | getmail | getmail | 4.44.0 | Yes |