Bugzilla – Bug 1174580
VUL-0: CVE-2020-15954: kmail: engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use
Last modified: 2021-08-09 12:44:30 UTC
CVE-2020-15954 KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use. Reference: https://bugs.kde.org/show_bug.cgi?id=423426 References: https://bugzilla.redhat.com/show_bug.cgi?id=1861078 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-15954 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15954 https://bugs.kde.org/show_bug.cgi?id=423426
We're checking whether the KDE security team was contacted about this issue.
So, - upstream was not contacted about this CVE, - they also don't think that's a security issue, only not very good default values