Bug 1174580 - (CVE-2020-15954) VUL-0: CVE-2020-15954: kmail: engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use
(CVE-2020-15954)
VUL-0: CVE-2020-15954: kmail: engages in unencrypted POP3 communication durin...
Status: NEW
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.1
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: E-Mail List
Security Team bot
https://smash.suse.de/issue/264275/
:
Depends on:
Blocks: NOSTARTTLS
  Show dependency treegraph
 
Reported: 2020-07-28 06:33 UTC by Alexandros Toptsoglou
Modified: 2021-08-09 12:44 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2020-07-28 06:33:48 UTC
CVE-2020-15954

KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.

Reference:
https://bugs.kde.org/show_bug.cgi?id=423426

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1861078
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-15954
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15954
https://bugs.kde.org/show_bug.cgi?id=423426
Comment 1 Christophe Marin 2020-07-28 08:23:14 UTC
We're checking whether the KDE security team was contacted about this issue.
Comment 2 Christophe Marin 2020-07-29 13:28:06 UTC
So,
- upstream was not contacted about this CVE,
- they also don't think that's a security issue, only not very good default values